To check HTTP headers, type a URL into Primary URL, leave Method on HEAD and select Scan. ToolzyLab's server requests the page, follows any redirects, and lists every response header with a security grade, missing headers, weak settings and recommended fixes. Switch Method to GET if a server handles HEAD requests badly.
How to use the HTTP header checker
- Enter the URL. Type it in Primary URL; https:// is added if you leave it off. Add a second address in Compare URL to scan two sites side by side.
- Choose scan options. HEAD is the default and fetches headers only. GET downloads the page too, which some servers need. If the server rejects a HEAD request or returns no headers, the tool retries once with GET automatically. Timeout sets how long to wait for the site: 5, 10 or 15 seconds.
- Scan. Select Scan or press Enter. Results show the grade, score, status, number of headers and redirects.
- Review and export. Work through Missing Security Headers, Weak or Misconfigured Findings and Recommendations, filter the header table, then use Copy raw headers, Copy JSON, Download JSON or Download PDF.
What the security headers checker looks for
Each scan starts at 100 points and loses points for missing or weak settings. The score maps to a grade: A from 90, B from 80, C from 65, D from 45, and F below that.
| Header | What it does | What the checker wants |
|---|---|---|
| Content-Security-Policy | Limits where scripts, styles and frames can load from, cutting XSS risk | Present, without 'unsafe-inline' or 'unsafe-eval', with object-src 'none' and frame-ancestors |
| Strict-Transport-Security | Tells browsers to use HTTPS only | max-age of at least 31536000 (one year) plus includeSubDomains |
| X-Frame-Options | Blocks clickjacking by controlling framing | DENY or SAMEORIGIN, or CSP frame-ancestors instead |
| X-Content-Type-Options | Stops MIME type sniffing | nosniff |
| Referrer-Policy | Controls how much of the URL is sent to other sites | Any value except unsafe-url, for example strict-origin-when-cross-origin |
| Permissions-Policy | Turns off browser features such as camera or geolocation | Present |
Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy and Cross-Origin-Embedder-Policy are listed under Good Findings when present. The scan also checks that plain HTTP redirects to HTTPS, inspects each Set-Cookie for HttpOnly, Secure and SameSite, and flags Server and X-Powered-By headers that reveal software versions.
One scoring note: the CSP frame-ancestors directive replaces X-Frame-Options, and the CSP specification tells browsers to ignore X-Frame-Options when both are set. So when a policy sets frame-ancestors, a missing X-Frame-Options costs no points and is listed under Good Findings as framing protection.
Common HTTP headers you'll see in the results
The All Response Headers table sorts headers into groups you can filter:
- Caching:
Cache-Control,ETag,Last-Modified,Expires,Age,Vary. The checker flags a response with none of these. - Content:
Content-Type,Content-Length,Content-Encoding. A missingContent-Encodingsuggests the response isn't compressed with gzip or Brotli. - CORS:
Access-Control-Allow-Originand related headers.*combined withAccess-Control-Allow-Credentials: trueis flagged as high risk. - Server and network:
Server,Via,Date,Location, and CDN headers such ascf-ray.
The scan sends the header Origin: https://toolzylab.com, because many APIs only return CORS headers when an Origin is present. If the server echoes that unrelated origin back in Access-Control-Allow-Origin, the checker warns that it reflects any origin, and rates it high risk when credentials are allowed. An empty CORS group still doesn't prove CORS is off, since some servers only answer CORS preflight requests. To read query strings in redirect URLs, paste them into the URL decoder.
How to check response headers yourself
This tool shows what ToolzyLab's server receives: no cookies, no login, and a user agent that starts with ToolzyLab-Header-Checker/4.0. CDNs and firewalls may answer it differently from your browser, and pages behind a login can't be scanned. To see the headers your own browser gets, open developer tools, go to the Network tab, reload, click the first request and look under Response Headers. From a terminal, curl -I https://example.com sends a HEAD request and prints the headers.
The checker follows up to 5 redirects and shows each hop's status code and Location under Redirect Chain. Timeout applies to each request, and a whole scan, including the extra checks below, is limited to 10 requests and 20 seconds. If that budget runs out, the remaining checks are shown as Not checked rather than as missing. Robots & Security.txt reports whether /robots.txt and /.well-known/security.txt respond, and SSL Certificate shows the subject, issuer, validity dates and days remaining, warning when fewer than 45 remain.
Are HTTP headers case-sensitive?
Header names aren't. RFC 9110 states that field names are case-insensitive, so Content-Type, content-type and CONTENT-TYPE are the same header. HTTP/2 goes further and requires names to be sent in lowercase, which is why browser tools often show them that way.
Header values are a different matter and depend on the header. Directive names like max-age are case-insensitive, but an ETag value, a cookie value or the path in a Location URL must match exactly. To spot what changed between two scans, copy the raw headers from each and paste them into the diff checker.
Frequently asked questions
What is an HTTP header checker?
It requests a URL and shows the HTTP response headers the server sends back, such as Content-Type, Cache-Control and security headers. This one also grades the security headers and suggests fixes.
How do I check the security headers of my website?
Enter your site's URL and select Scan. Missing Security Headers lists what to add, and Recommendations gives a copy-ready header line for each, such as X-Content-Type-Options: nosniff.
Should I use HEAD or GET?
Start with HEAD, which asks for headers without the page body. Use GET if the results look incomplete, because some servers send different headers, or none, for HEAD requests.
Can I scan localhost or an internal IP address?
No. The server only connects to public addresses on ports 80 and 443 and blocks private, loopback and reserved IP ranges. Use curl or your browser's developer tools for local sites.
Why did my scan fail?
Common causes are a site slower than the 8-second limit, more than 5 redirects, a blocked or private address, or reaching the limit of a few scans per minute. Wait a minute and try again, or switch Method to GET.
Are my scans saved?
The last 20 scanned URLs, with their grades, are kept in Scan History in your browser's local storage.