DNS Lookup
Check any domain's DNS records online: A, AAAA, CNAME, MX, NS, TXT, SOA and CAA. See where a domain points, its mail servers and its nameservers.
Check the HTTP response headers of any URL: status code, server, caching, Last-Modified, redirects and security headers like HSTS and CSP. Free.
This tool asks our server for public information only. Nothing you enter is stored.
Enter a URL and see the response headers its server sends back: the status code (200, 301, 404 and so on), Server, Content-Type, caching headers such as Cache-Control, ETag and Last-Modified, cookies, and the headers of every redirect on the way. The checker also flags the main security headers (Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy) so you can see at a glance which ones are missing.
When a browser asks for a page it sends request headers (which browser it is, which languages it accepts, its cookies), and the server answers with response headers before the page itself. They say what the content is, how long to cache it, where to redirect, and which security rules apply. They never show on the page, which is why a checker helps. A typical response:
HTTP/2 200
content-type: text/html; charset=UTF-8
cache-control: max-age=600
last-modified: Fri, 09 Oct 2026 08:12:40 GMT
strict-transport-security: max-age=31536000; includeSubDomains
x-content-type-options: nosniff
server: nginx Open the page, press F12 to open DevTools, choose the Network tab and reload. Click the first row (the page itself) and the Headers tab shows the response headers and the request headers your browser sent. From a terminal, curl -I https://example.com prints only the headers. To see the headers your own browser sends, open our What is my IP tool: it shows your user agent and languages.
PHP's get_headers() fetches the headers of any URL, and header() sets your own before any output. If you were looking on GitHub for a header checker script, these few lines are the core of one.
<?php
// read the headers of another site (true = as an array by name)
print_r(get_headers('https://example.com', true));
// send your own headers (before any output)
header('X-Content-Type-Options: nosniff');
header('Referrer-Policy: strict-origin-when-cross-origin');
header('Strict-Transport-Security: max-age=31536000; includeSubDomains'); Last-Modified tells browsers and search engines when the page last changed. On the next visit they send If-Modified-Since, and the server can answer 304 Not Modified with no body, which saves bandwidth. ETag works the same way with a fingerprint. If your pages send neither, your server or CMS isn't adding them.
The six headers flagged above protect visitors from clickjacking, content-type sniffing, leaking full URLs to other sites and being sent over plain HTTP. Adding them takes a few lines in your server config or in PHP, as above. Run the check again after the change to confirm they arrive.
GuideNginx vs Apache vs LiteSpeed: Which Web Server Should You Use?
Enter the URL above and press Check headers. You can also use the Network tab in your browser's DevTools, or curl -I in a terminal.
Put your site's address in the box above to see the headers your server sends. To see the headers your browser sends, use our What is my IP tool.
Enter any page address here. You get the status code, every response header and each redirect, the same way a browser or Googlebot sees them.
A name and value sent before the page, such as Content-Type: text/html. Headers tell the browser how to handle the response: its type, caching, cookies, redirects and security rules.
Your browser sends cookies and may be logged in, and a CDN can answer from a server near you. Our server visits as a new visitor from its own location.
No. We fetch the headers, show them, and keep nothing.
Check any domain's DNS records online: A, AAAA, CNAME, MX, NS, TXT, SOA and CAA. See where a domain points, its mail servers and its nameservers.
Trace every redirect of a URL: each hop's status code (301, 302, 307, 308), its Location, the server and meta refresh. Find redirect chains and loops.
See your public IP address (IPv4 or IPv6), its reverse host name, and what your browser tells websites. Works on phones and computers.