📋
HTTP Header Inspector
Fetch the real HTTP response headers of any URL and audit the security headers every modern site should send.
Inspect a URL
The server's actual response headers are fetched live
Why Check Response Headers?
🛡️ Security
- Missing CSP leaves the page open to injected scripts
- No HSTS lets attackers downgrade HTTPS to HTTP
- No X-Frame-Options enables clickjacking attacks
⚡ Performance & Debugging
- Cache-Control decides whether visitors get fast cached responses
- CDN headers (cf-ray, x-vercel-id, x-served-by) reveal which edge served you
- Set-Cookie flags (Secure, HttpOnly, SameSite) show cookie hygiene
About HTTP Header Inspector
Inspect the actual HTTP response headers a server sends for any URL. See security headers (CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy), caching directives, content types, and cookies — with an instant audit that flags which recommended security headers are missing. Perfect for hardening your own sites and debugging CDN or caching behavior.
🎯 Who is this tool for?
Web DevelopersDevOps EngineersSecurity EnthusiastsSite Owners
✨ Key Features
- Real response headers fetched live from the target server
- Security header audit with pass/missing flags
- Status code, redirect chain result, and response time
- Full raw header list (caching, cookies, server, CDN)
- Page title and content size preview
- SSRF-protected: private and local addresses are blocked
🚀 How to Use
- 1Enter any public URL (e.g., https://example.com).
- 2Click 'Inspect Headers' to fetch the live response.
- 3Review the audit of recommended security headers.
- 4Expand the raw headers to see everything the server sent.
Frequently Asked Questions