Skip to content

HTTP Headers Viewer

Free HTTP headers checker online: view response headers for any URL, highlight CSP, HSTS, X-Frame-Options and more. Works in your browser with an honest CORS fallback.

  • View HTTP response headers for a public URL
  • Security headers highlight — CSP, HSTS, X-Frame-Options, and more
  • Direct CORS fetch first; cors.lol proxy fallback when blocked
  • Demo mode against httpbin.org (always works for teaching)
  • Copy raw header dump; see which fetch path succeeded

Headers

Direct CORS first; fallback via cors.lol — URL leaves the browser; we do not log it

Tries a direct CORS fetch first. If the browser blocks it (or only safelisted headers are visible), falls back to the cors.lol proxy. Demo always uses httpbin.org.

Enter a URL to view HTTP response headers, or run Demo to see security headers against httpbin.org.

How to check HTTP headers online

  1. 01

    Paste a URL

    Enter a full URL or bare hostname (https is added automatically).

  2. 02

    Check headers

    The tool tries a direct CORS fetch first. If the browser blocks it, it retries through the cors.lol proxy and labels which path worked.

  3. 03

    Review security headers

    CSP, HSTS, X-Frame-Options and related headers are highlighted and summarized as present or missing.

  4. 04

    Use Demo if you just want to learn

    Demo loads httpbin.org with sample security headers so you can see the UI without depending on third-party CORS.

What an HTTP headers checker shows you#

Every HTTP response starts with a status line and a list of response headers — metadata the server sends before the body. A response headers checker (or HTTP headers viewer) dumps that metadata so you can see caching rules (Cache-Control, ETag), content type, redirects (Location), CORS (Access-Control-Allow-Origin), and security policy headers without opening DevTools on every site.

People search for “http headers checker online”, “check http headers of a website”, and “get http headers” when they are debugging CDN misconfiguration, verifying HSTS after a cert rollout, or confirming that a staging host is not leaking X-Powered-By / Server details. This tool is aimed at that quick check: paste a URL, read the table, copy the dump.

Security headers to check (CSP, HSTS, framing)#

When you check HTTP headers security posture, six names matter most on modern sites: Content-Security-Policy (CSP) limits script and resource origins; Strict-Transport-Security (HSTS) forces HTTPS; X-Frame-Options (or CSP frame-ancestors) blocks clickjacking; X-Content-Type-Options: nosniff stops MIME sniffing; Referrer-Policy controls how much URL data leaves with navigations; Permissions-Policy gates powerful browser APIs. This viewer highlights those headers when present and lists checklist gaps when they are missing from the dump you received.

Missing security headers are a signal, not an automatic “fail the site” verdict — APIs, static asset hosts, and intentionally embeddable widgets often omit framing or CSP by design. Still, for a public marketing site, seeing CSP + HSTS + nosniff is a healthy baseline.

Why browsers cannot always show every header#

A pure fetch() from a static page is subject to CORS. Even when a request “succeeds,” JavaScript may only read CORS-safelisted response headers (Content-Type, Content-Length, and a few others) unless the target sends Access-Control-Expose-Headers. That is why many “view HTTP headers” sites need a server-side hop.

This tool’s honest strategy: try a direct CORS fetch first (best when the API already allows your origin). On failure — or when the direct dump looks CORS-limited — retry via the public cors.lol proxy and show which path worked. Free proxies rate-limit; if you hit HTTP 429, wait and retry, use Demo (httpbin), or fall back to curl -I locally. DevSEOCraft does not run its own header-fetch backend on Cloudflare Pages for this tool.

Privacy and third-party fallback#

Your URL is processed in the browser. On the direct path, only the target host sees the request. On the proxy path, cors.lol receives the URL to fetch it server-side. We do not log inputs on DevSEOCraft servers. Prefer curl -I or browser DevTools when the URL itself is sensitive.

Frequently asked questions

Is this a free HTTP headers checker online?

Yes. It is a free HTTP headers checker / response headers checker that runs in your browser. No account is required.

Why do I only see Content-Type and a few headers?

Browsers hide most response headers from JavaScript unless the site allows them via CORS (`Access-Control-Expose-Headers`). Use “Retry via proxy” so cors.lol can return a fuller dump, or run curl -I locally for an authoritative view.

How do I check HTTP headers security (CSP, HSTS)?

Run the check and look at the highlighted security rows and the present/missing checklist (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy). Demo mode injects sample values via httpbin if you want to see the UI first.

What is the cors.lol fallback?

When a direct CORS fetch fails (or looks limited), the tool requests https://api.cors.lol/?url=… so a third-party proxy fetches the target and returns the response to your browser. The UI labels the path as “Via cors.lol proxy.” Free usage may be rate-limited.

Can I check headers of any website?

Public http(s) URLs only. Private networks, authenticated apps, and hosts that block the proxy will fail. Followed redirects show the final response’s headers.

Is my URL private?

DevSEOCraft does not receive or log the URL on our servers. A direct fetch talks only to the target. A proxy fetch sends the URL to cors.lol. Use curl or DevTools for sensitive endpoints.

How is this different from curl -I or browser DevTools?

curl -I and the Network panel see every header without CORS limits. This page is a quick online check with an explicit proxy fallback — convenient, not a replacement for local tooling when you need a complete authoritative dump.

Dev + SEO

Morse Code Converter

Convert text to Morse code and back with audio beeps and a light flash.