What an HTTP headers checker shows you#
Every HTTP response starts with a status line and a list of response headers — metadata the server sends before the body. A response headers checker (or HTTP headers viewer) dumps that metadata so you can see caching rules (Cache-Control, ETag), content type, redirects (Location), CORS (Access-Control-Allow-Origin), and security policy headers without opening DevTools on every site.
People search for “http headers checker online”, “check http headers of a website”, and “get http headers” when they are debugging CDN misconfiguration, verifying HSTS after a cert rollout, or confirming that a staging host is not leaking X-Powered-By / Server details. This tool is aimed at that quick check: paste a URL, read the table, copy the dump.
Security headers to check (CSP, HSTS, framing)#
When you check HTTP headers security posture, six names matter most on modern sites: Content-Security-Policy (CSP) limits script and resource origins; Strict-Transport-Security (HSTS) forces HTTPS; X-Frame-Options (or CSP frame-ancestors) blocks clickjacking; X-Content-Type-Options: nosniff stops MIME sniffing; Referrer-Policy controls how much URL data leaves with navigations; Permissions-Policy gates powerful browser APIs. This viewer highlights those headers when present and lists checklist gaps when they are missing from the dump you received.
Missing security headers are a signal, not an automatic “fail the site” verdict — APIs, static asset hosts, and intentionally embeddable widgets often omit framing or CSP by design. Still, for a public marketing site, seeing CSP + HSTS + nosniff is a healthy baseline.
Why browsers cannot always show every header#
A pure fetch() from a static page is subject to CORS. Even when a request “succeeds,” JavaScript may only read CORS-safelisted response headers (Content-Type, Content-Length, and a few others) unless the target sends Access-Control-Expose-Headers. That is why many “view HTTP headers” sites need a server-side hop.
This tool’s honest strategy: try a direct CORS fetch first (best when the API already allows your origin). On failure — or when the direct dump looks CORS-limited — retry via the public cors.lol proxy and show which path worked. Free proxies rate-limit; if you hit HTTP 429, wait and retry, use Demo (httpbin), or fall back to curl -I locally. DevSEOCraft does not run its own header-fetch backend on Cloudflare Pages for this tool.
Privacy and third-party fallback#
Your URL is processed in the browser. On the direct path, only the target host sees the request. On the proxy path, cors.lol receives the URL to fetch it server-side. We do not log inputs on DevSEOCraft servers. Prefer curl -I or browser DevTools when the URL itself is sensitive.