HTTP Headers Checker

Check the HTTP response headers of any URL: status code, server, caching, Last-Modified, redirects and security headers like HSTS and CSP. Free.

This tool asks our server for public information only. Nothing you enter is stored.

How to use the HTTP Headers Checker

  1. Enter a URL, such as https://example.com.
  2. Press Check headers. Our server requests the page and follows any redirects.
  3. Read the status, the headers of each step and the security headers that are missing.

About this tool

Enter a URL and see the response headers its server sends back: the status code (200, 301, 404 and so on), Server, Content-Type, caching headers such as Cache-Control, ETag and Last-Modified, cookies, and the headers of every redirect on the way. The checker also flags the main security headers (Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy) so you can see at a glance which ones are missing.

What is an HTTP header?

When a browser asks for a page it sends request headers (which browser it is, which languages it accepts, its cookies), and the server answers with response headers before the page itself. They say what the content is, how long to cache it, where to redirect, and which security rules apply. They never show on the page, which is why a checker helps. A typical response:

HTTP/2 200
content-type: text/html; charset=UTF-8
cache-control: max-age=600
last-modified: Fri, 09 Oct 2026 08:12:40 GMT
strict-transport-security: max-age=31536000; includeSubDomains
x-content-type-options: nosniff
server: nginx

Check HTTP headers in Chrome

Open the page, press F12 to open DevTools, choose the Network tab and reload. Click the first row (the page itself) and the Headers tab shows the response headers and the request headers your browser sent. From a terminal, curl -I https://example.com prints only the headers. To see the headers your own browser sends, open our What is my IP tool: it shows your user agent and languages.

Read and set headers in PHP

PHP's get_headers() fetches the headers of any URL, and header() sets your own before any output. If you were looking on GitHub for a header checker script, these few lines are the core of one.

<?php
// read the headers of another site (true = as an array by name)
print_r(get_headers('https://example.com', true));

// send your own headers (before any output)
header('X-Content-Type-Options: nosniff');
header('Referrer-Policy: strict-origin-when-cross-origin');
header('Strict-Transport-Security: max-age=31536000; includeSubDomains');

Last-Modified and caching

Last-Modified tells browsers and search engines when the page last changed. On the next visit they send If-Modified-Since, and the server can answer 304 Not Modified with no body, which saves bandwidth. ETag works the same way with a fingerprint. If your pages send neither, your server or CMS isn't adding them.

The security headers check

The six headers flagged above protect visitors from clickjacking, content-type sniffing, leaking full URLs to other sites and being sent over plain HTTP. Adding them takes a few lines in your server config or in PHP, as above. Run the check again after the change to confirm they arrive.

GuideNginx vs Apache vs LiteSpeed: Which Web Server Should You Use?

Frequently asked questions

How do I check HTTP headers?

Enter the URL above and press Check headers. You can also use the Network tab in your browser's DevTools, or curl -I in a terminal.

How can I check my HTTP headers online?

Put your site's address in the box above to see the headers your server sends. To see the headers your browser sends, use our What is my IP tool.

How do I check the header of a website?

Enter any page address here. You get the status code, every response header and each redirect, the same way a browser or Googlebot sees them.

What is an HTTP header?

A name and value sent before the page, such as Content-Type: text/html. Headers tell the browser how to handle the response: its type, caching, cookies, redirects and security rules.

Why do I see different headers in my browser?

Your browser sends cookies and may be logged in, and a CDN can answer from a server near you. Our server visits as a new visitor from its own location.

Is anything stored?

No. We fetch the headers, show them, and keep nothing.

More network tools

Domain, server and network

All 31 free tools →
Network tool · Checks live sites

DNS Lookup

Check any domain's DNS records online: A, AAAA, CNAME, MX, NS, TXT, SOA and CAA. See where a domain points, its mail servers and its nameservers.

Free · No sign-upOpen tool
Network tool · Checks live sites

Redirect Checker

Trace every redirect of a URL: each hop's status code (301, 302, 307, 308), its Location, the server and meta refresh. Find redirect chains and loops.

Free · No sign-upOpen tool
Network tool · Checks live sites

What Is My IP

See your public IP address (IPv4 or IPv6), its reverse host name, and what your browser tells websites. Works on phones and computers.

Free · No sign-upOpen tool