📋

HTTP Header Inspector

Fetch the real HTTP response headers of any URL and audit the security headers every modern site should send.

Inspect a URL
The server's actual response headers are fetched live
Why Check Response Headers?

🛡️ Security

  • Missing CSP leaves the page open to injected scripts
  • No HSTS lets attackers downgrade HTTPS to HTTP
  • No X-Frame-Options enables clickjacking attacks

⚡ Performance & Debugging

  • Cache-Control decides whether visitors get fast cached responses
  • CDN headers (cf-ray, x-vercel-id, x-served-by) reveal which edge served you
  • Set-Cookie flags (Secure, HttpOnly, SameSite) show cookie hygiene
About HTTP Header Inspector

Inspect the actual HTTP response headers a server sends for any URL. See security headers (CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy), caching directives, content types, and cookies — with an instant audit that flags which recommended security headers are missing. Perfect for hardening your own sites and debugging CDN or caching behavior.

🎯 Who is this tool for?

Web DevelopersDevOps EngineersSecurity EnthusiastsSite Owners

✨ Key Features

  • Real response headers fetched live from the target server
  • Security header audit with pass/missing flags
  • Status code, redirect chain result, and response time
  • Full raw header list (caching, cookies, server, CDN)
  • Page title and content size preview
  • SSRF-protected: private and local addresses are blocked

🚀 How to Use

  1. 1Enter any public URL (e.g., https://example.com).
  2. 2Click 'Inspect Headers' to fetch the live response.
  3. 3Review the audit of recommended security headers.
  4. 4Expand the raw headers to see everything the server sent.
Frequently Asked Questions