sysadmintools

HTTP Headers Checker

Inspect response headers, redirect chains, and security headers for any URL. Useful for debugging redirects, CORS, and server config.

Reading security headers honestly

This fetches a URL, follows each redirect in turn, and reports the security headers on the final response. Because redirects are involved, every hop is validated before it is fetched, so a chain pointing at an internal address is refused rather than followed. Many chains also cross domains, and headers set on the first hop may not survive intact to the last one, which is where the report is taken.

A missing header is not automatically a vulnerability, and a present one is not proof of safety. HSTS is the clearest example: it is only honoured over HTTPS and ignored on the first plaintext visit, so it offers nothing to a user who has never loaded the site securely. The header states intent, not outcome. Likewise, a strong frame-ancestors or X-Content-Type-Options setting on the HTML says nothing about a JSON endpoint on the same host.

CSP is only as strong as its weakest directive. A permissive script-src, or a wildcard anywhere in the policy, can undo the rest, and a report-only policy blocks nothing at all, collecting violations instead. Treating CSP-Report-Only as enforced protection is a frequent mistake.

Headers are also not necessarily the origin's. A CDN or reverse proxy can add, rewrite or strip them before the response reaches you, so what this page sees may differ from what the application itself sets. When something looks wrong, inspect at the origin before touching application code, and re-run after any edge configuration change. A header that appears fixed at the CDN but absent from the application is a latency problem waiting to surface the next time the cache is bypassed.

Related reading