HTTP Headers Checker
Inspect response headers, redirect chains, and security headers for any URL. Useful for debugging redirects, CORS, and server config.
Reading security headers honestly
This fetches a URL, follows each redirect in turn, and reports the security headers on the final response. Because redirects are involved, every hop is validated before it is fetched, so a chain pointing at an internal address is refused rather than followed. Many chains also cross domains, and headers set on the first hop may not survive intact to the last one, which is where the report is taken.
A missing header is not automatically a vulnerability, and a present one is not proof of safety. HSTS is the clearest example: it is only honoured over HTTPS and ignored on the first plaintext visit, so it offers nothing to a user who has never loaded the site securely. The header states intent, not outcome. Likewise, a strong frame-ancestors or X-Content-Type-Options setting on the HTML says nothing about a JSON endpoint on the same host.
CSP is only as strong as its weakest directive. A permissive script-src, or a wildcard anywhere in the policy, can undo the rest, and a report-only policy blocks nothing at all, collecting violations instead. Treating CSP-Report-Only as enforced protection is a frequent mistake.
Headers are also not necessarily the origin's. A CDN or reverse proxy can add, rewrite or strip them before the response reaches you, so what this page sees may differ from what the application itself sets. When something looks wrong, inspect at the origin before touching application code, and re-run after any edge configuration change. A header that appears fixed at the CDN but absent from the application is a latency problem waiting to surface the next time the cache is bypassed.
Related reading
- How to check an SSL/TLS certificate (and what to look for)Every HTTPS site relies on a TLS certificate. Here's how to read one, what each field actually means, and the things that should make you suspicious.
- How to read an open port (and when to actually worry)An 'open port' isn't a vulnerability by itself — it's information. Here's how to tell whether a port being open is fine, suspicious, or actively dangerous, and what to do about each case.
- How to check DNS propagation (and how long it actually takes)Just changed an A record and your friend in another country still sees the old site? That's DNS propagation. Here's how to verify when it's actually done — and how long it can take.