📡 HTTP Headers Analyzer
Examine HTTP response headers from any website to analyze server configuration, caching policies, and security settings.
What you get back
Paste a full URL, including the https://, and the tool makes
one request from our server and prints every response header it received,
name and value, unedited. No page is rendered and no script is run, so
what you see is the server's own description of what it just sent - the
part of a response a visitor never notices and a crawler pays close
attention to.
Headers are also where a surprising amount of behaviour is decided that has no equivalent anywhere in your HTML.
The lines worth reading first
| Header | Why it matters |
|---|---|
cache-control | Decides how long browsers and CDNs may reuse the response. Missing, everything downstream guesses. |
content-encoding | gzip or br means the text was compressed. Absent on HTML or CSS, you are shipping several times more bytes than you need to. |
x-robots-tag | Carries noindex and nofollow at the header level. It applies to PDFs and images, and it overrides nothing in your HTML because it is invisible there. |
strict-transport-security | Tells browsers to use HTTPS for this host for the given number of seconds, without asking first. |
vary | Names the request headers that change the response. Get it wrong and a CDN serves one visitor's variant to everybody. |
content-type | Including the charset. A mislabelled charset is the usual cause of mangled accented characters. |
X-Robots-Tag: noindex
set on a whole directory by a server rule is invisible in view-source and
removes the page just as thoroughly as a meta tag would.Frequently asked questions
Which security headers should I be sending?
Four earn their place: Strict-Transport-Security,
Content-Security-Policy,
X-Content-Type-Options: nosniff and a
Referrer-Policy. X-Frame-Options is worth
keeping for old browsers but is superseded by CSP's
frame-ancestors. X-XSS-Protection is obsolete
- the filter it controlled was removed from browsers years ago, and
sending it does nothing.
What does cache-control: no-cache actually mean?
Not what it reads like. no-cache allows the response to be
stored but requires the browser to check with the server before reusing
it, which usually ends in a cheap 304. The one that forbids storing
anything is no-store. If you meant "never keep this", you
want the second.
Why do my headers look different from what my code sets?
Because something sits in between. A CDN, a reverse proxy or the host's
own edge can add, rewrite or strip headers after your application is
finished with the response - that is where an unexpected
server name or an extra caching directive usually comes
from. Compare this output against a request straight to the origin to
see which layer is responsible.