Skip to content
← All tools

[ CHECK / [HEAD] ]

HTTP header checker

Inspect selected security and caching headers from a website response.

↗ Checked on request

01 / Your URL

Preparing the checker…

Sends a pinned HEAD request from our server and follows at most three validated redirects. Some destinations are blocked by Cloudflare. Results are not saved to workspace history.

02 / Your result

Your result will appear here.
Start with your own input or try an example.

What it does

Send a small HEAD request and inspect a limited set of response headers, including cache control, HSTS, content security policy, and content type. Review redirects and the exact URL that responded. The notes explain the observed headers without assigning a security score.

Useful when

  • Check whether a deployed caching header is returned.
  • Inspect HSTS or content security policy on a website response.
  • See which URL responded after a short redirect chain.

How to use it

  1. Enter a public HTTP or HTTPS URL.
  2. Complete verification if requested, then inspect the response.
  3. Review the status, selected headers, and context notes, or copy the snapshot.

A few useful details

Does this certify that a website is secure?

No. Header presence is only an observation. The checker does not validate a whole policy, audit content, test a login session, or guarantee a site’s safety. Appropriate headers depend on the response and application.

Are all response headers shown?

No. Only a fixed set of security, cache, and content headers is returned. Cookies, authentication challenges, and arbitrary headers are excluded. HEAD responses may differ from browser GET requests.

Why might a live website be inconclusive?

Cloudflare’s socket service blocks some destinations, including Cloudflare-owned IP ranges. DNS or TLS can also fail. The checker does not bypass these restrictions or fall back to an unpinned request, and an inconclusive result does not mean the site is down.