HTTP Header Checker

Inspect the HTTP response headers for any URL. Audit the security headers that protect your site and confirm the configuration that search engines read.

Header Audit Security

Header inspection runs through the NFlow server, so it works on any site regardless of CORS.

Why Response Headers Are the First Line of Defense

HTTP response headers are the first thing a browser or crawler receives from your server. They carry information about security, caching, and SEO that is not visible on the page itself. A missing security header is an open door for attacks such as clickjacking, MIME sniffing, and cross site scripting. A strict Content Security Policy and HTTP Strict Transport Security header reduce those risks in a measurable way.

Search engines factor page speed and security into ranking signals. Cache headers such as Cache-Control and ETag help browsers reuse content, which speeds up repeat visits. SEO headers such as the X-Robots-Tag and the Link header (canonical, hreflang) tell crawlers how to treat a page. When these headers are wrong or missing, crawlers may waste resources or misread your intent.

A quick check after every deploy

This tool gives you a complete view of every header your server returns, grouped by purpose, with a grade for the security headers that matter most. A header check after a deploy can catch a misplaced directive before it affects real users or search visibility.

How to Read the Security Grade and Header Groups

Enter the full URL you want to inspect, including the protocol, and click Check Headers. The results show the HTTP status, the final URL after redirects, and a security grade based on five core headers: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy.

The Security Headers section lists all five and marks each present or missing with a short explanation of what it controls. Caching, SEO, and General groups list only the headers your server actually sent, so the report stays focused. The raw header block at the bottom is the exact text your server returned, ready to copy into a ticket or report.

Run this check after any server or CDN change and compare results over time to confirm your security posture stays consistent as your site grows.