📡 HTTP Headers Analyzer

Examine HTTP response headers from any website to analyze server configuration, caching policies, and security settings.

💡 Tip: Enter a complete URL and click "Analyze Headers" to view HTTP response headers.
Enter a website URL and click "Analyze Headers" to view results.

What you get back

Paste a full URL, including the https://, and the tool makes one request from our server and prints every response header it received, name and value, unedited. No page is rendered and no script is run, so what you see is the server's own description of what it just sent - the part of a response a visitor never notices and a crawler pays close attention to.

Headers are also where a surprising amount of behaviour is decided that has no equivalent anywhere in your HTML.

The lines worth reading first

HeaderWhy it matters
cache-controlDecides how long browsers and CDNs may reuse the response. Missing, everything downstream guesses.
content-encodinggzip or br means the text was compressed. Absent on HTML or CSS, you are shipping several times more bytes than you need to.
x-robots-tagCarries noindex and nofollow at the header level. It applies to PDFs and images, and it overrides nothing in your HTML because it is invisible there.
strict-transport-securityTells browsers to use HTTPS for this host for the given number of seconds, without asking first.
varyNames the request headers that change the response. Get it wrong and a CDN serves one visitor's variant to everybody.
content-typeIncluding the charset. A mislabelled charset is the usual cause of mangled accented characters.
A page that vanished from search with nothing wrong in its HTML is worth checking here first. X-Robots-Tag: noindex set on a whole directory by a server rule is invisible in view-source and removes the page just as thoroughly as a meta tag would.

Frequently asked questions

Which security headers should I be sending?

Four earn their place: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options: nosniff and a Referrer-Policy. X-Frame-Options is worth keeping for old browsers but is superseded by CSP's frame-ancestors. X-XSS-Protection is obsolete - the filter it controlled was removed from browsers years ago, and sending it does nothing.

What does cache-control: no-cache actually mean?

Not what it reads like. no-cache allows the response to be stored but requires the browser to check with the server before reusing it, which usually ends in a cheap 304. The one that forbids storing anything is no-store. If you meant "never keep this", you want the second.

Why do my headers look different from what my code sets?

Because something sits in between. A CDN, a reverse proxy or the host's own edge can add, rewrite or strip headers after your application is finished with the response - that is where an unexpected server name or an extra caching directive usually comes from. Compare this output against a request straight to the origin to see which layer is responsible.