Skip to content

HTTP Header Checker and Security Headers Scan

Enter a URL to see every response header it sends, follow its redirects, and get an A to F grade for security headers like HSTS and Content-Security-Policy, with copy-ready fixes.

Scan setup

The scan runs on ToolzyLab's server, which requests the page and reads its headers. Only public URLs are allowed.

Waiting for URL

URLs

Add a second URL to compare two sites.

Options

Request method, timeout and result filters.

Ready. Enter one or two public URLs to begin.
ModeSingle
Primary Grade
—
Primary Score
—
Primary StatusWaiting
Primary Headers0
Primary Redirects0
Compare Grade
—
Compare Score
—
Compare Status—
Score Difference—

Overview

Main result summary for the current primary scan.

Method: HEAD Time: n/a HTTPS: n/a HTTP to HTTPS: n/a
No analysis yetRun a scan to see the overview.

Missing Security Headers

Important headers that are missing and should be added.

0 items
Missing findings will appear here.

Weak or Misconfigured Findings

Headers found, but still not configured strongly enough.

0 items
Weak findings will appear here.

Recommendations

Copy-ready examples and suggested fixes.

0 items
Recommendations will appear here.

All Response Headers

Searchable, filterable header table for the primary result.

Header results will appear here after a successful request.

Compare View

Side-by-side result comparison appears here when second URL is used.

Primary

WaitingNo compare data yet.

Compare

WaitingNo compare data yet.

Good Findings

Strong headers and positive checks already present.

0 items
Good findings will appear here.

Redirect Chain

Every redirect hop before the final response.

Redirect chain will appear here if redirects happen.

SSL Certificate

Certificate snapshot for HTTPS targets.

No SSL data yetRun a scan on an HTTPS URL.

Robots & Security.txt

Presence checks for robots.txt and security.txt.

No checks yetRun a scan to check robots.txt and security.txt.

Cookies & Delivery

Cookies, caching, compression, CORS, and server exposure.

Delivery analysis will appear here.

Raw Headers

Plain text output for quick copying.

No raw headers yet.

Scan History

Recent scans saved in the browser.

No saved scans yet.

The URL you enter is requested by ToolzyLab's server, which sends back the headers and the analysis. Only public HTTP and HTTPS addresses on ports 80 and 443 can be scanned, and each visitor can run a few scans per minute.

To check HTTP headers, type a URL into Primary URL, leave Method on HEAD and select Scan. ToolzyLab's server requests the page, follows any redirects, and lists every response header with a security grade, missing headers, weak settings and recommended fixes. Switch Method to GET if a server handles HEAD requests badly.

How to use the HTTP header checker

  1. Enter the URL. Type it in Primary URL; https:// is added if you leave it off. Add a second address in Compare URL to scan two sites side by side.
  2. Choose scan options. HEAD is the default and fetches headers only. GET downloads the page too, which some servers need. If the server rejects a HEAD request or returns no headers, the tool retries once with GET automatically. Timeout sets how long to wait for the site: 5, 10 or 15 seconds.
  3. Scan. Select Scan or press Enter. Results show the grade, score, status, number of headers and redirects.
  4. Review and export. Work through Missing Security Headers, Weak or Misconfigured Findings and Recommendations, filter the header table, then use Copy raw headers, Copy JSON, Download JSON or Download PDF.

What the security headers checker looks for

Each scan starts at 100 points and loses points for missing or weak settings. The score maps to a grade: A from 90, B from 80, C from 65, D from 45, and F below that.

HeaderWhat it doesWhat the checker wants
Content-Security-PolicyLimits where scripts, styles and frames can load from, cutting XSS riskPresent, without 'unsafe-inline' or 'unsafe-eval', with object-src 'none' and frame-ancestors
Strict-Transport-SecurityTells browsers to use HTTPS onlymax-age of at least 31536000 (one year) plus includeSubDomains
X-Frame-OptionsBlocks clickjacking by controlling framingDENY or SAMEORIGIN, or CSP frame-ancestors instead
X-Content-Type-OptionsStops MIME type sniffingnosniff
Referrer-PolicyControls how much of the URL is sent to other sitesAny value except unsafe-url, for example strict-origin-when-cross-origin
Permissions-PolicyTurns off browser features such as camera or geolocationPresent

Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy and Cross-Origin-Embedder-Policy are listed under Good Findings when present. The scan also checks that plain HTTP redirects to HTTPS, inspects each Set-Cookie for HttpOnly, Secure and SameSite, and flags Server and X-Powered-By headers that reveal software versions.

One scoring note: the CSP frame-ancestors directive replaces X-Frame-Options, and the CSP specification tells browsers to ignore X-Frame-Options when both are set. So when a policy sets frame-ancestors, a missing X-Frame-Options costs no points and is listed under Good Findings as framing protection.

Common HTTP headers you'll see in the results

The All Response Headers table sorts headers into groups you can filter:

  • Caching: Cache-Control, ETag, Last-Modified, Expires, Age, Vary. The checker flags a response with none of these.
  • Content: Content-Type, Content-Length, Content-Encoding. A missing Content-Encoding suggests the response isn't compressed with gzip or Brotli.
  • CORS: Access-Control-Allow-Origin and related headers. * combined with Access-Control-Allow-Credentials: true is flagged as high risk.
  • Server and network: Server, Via, Date, Location, and CDN headers such as cf-ray.

The scan sends the header Origin: https://toolzylab.com, because many APIs only return CORS headers when an Origin is present. If the server echoes that unrelated origin back in Access-Control-Allow-Origin, the checker warns that it reflects any origin, and rates it high risk when credentials are allowed. An empty CORS group still doesn't prove CORS is off, since some servers only answer CORS preflight requests. To read query strings in redirect URLs, paste them into the URL decoder.

How to check response headers yourself

This tool shows what ToolzyLab's server receives: no cookies, no login, and a user agent that starts with ToolzyLab-Header-Checker/4.0. CDNs and firewalls may answer it differently from your browser, and pages behind a login can't be scanned. To see the headers your own browser gets, open developer tools, go to the Network tab, reload, click the first request and look under Response Headers. From a terminal, curl -I https://example.com sends a HEAD request and prints the headers.

The checker follows up to 5 redirects and shows each hop's status code and Location under Redirect Chain. Timeout applies to each request, and a whole scan, including the extra checks below, is limited to 10 requests and 20 seconds. If that budget runs out, the remaining checks are shown as Not checked rather than as missing. Robots & Security.txt reports whether /robots.txt and /.well-known/security.txt respond, and SSL Certificate shows the subject, issuer, validity dates and days remaining, warning when fewer than 45 remain.

Are HTTP headers case-sensitive?

Header names aren't. RFC 9110 states that field names are case-insensitive, so Content-Type, content-type and CONTENT-TYPE are the same header. HTTP/2 goes further and requires names to be sent in lowercase, which is why browser tools often show them that way.

Header values are a different matter and depend on the header. Directive names like max-age are case-insensitive, but an ETag value, a cookie value or the path in a Location URL must match exactly. To spot what changed between two scans, copy the raw headers from each and paste them into the diff checker.

Frequently asked questions

What is an HTTP header checker?

It requests a URL and shows the HTTP response headers the server sends back, such as Content-Type, Cache-Control and security headers. This one also grades the security headers and suggests fixes.

How do I check the security headers of my website?

Enter your site's URL and select Scan. Missing Security Headers lists what to add, and Recommendations gives a copy-ready header line for each, such as X-Content-Type-Options: nosniff.

Should I use HEAD or GET?

Start with HEAD, which asks for headers without the page body. Use GET if the results look incomplete, because some servers send different headers, or none, for HEAD requests.

Can I scan localhost or an internal IP address?

No. The server only connects to public addresses on ports 80 and 443 and blocks private, loopback and reserved IP ranges. Use curl or your browser's developer tools for local sites.

Why did my scan fail?

Common causes are a site slower than the 8-second limit, more than 5 redirects, a blocked or private address, or reaching the limit of a few scans per minute. Wait a minute and try again, or switch Method to GET.

Are my scans saved?

The last 20 scanned URLs, with their grades, are kept in Scan History in your browser's local storage.

Updated 11 October 2026Reviewed by the ToolzyLab teamHow we test our tools