HTTP header checker
See the HTTP status and every response header a website sends, for the final page and each redirect on the way.
Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.
What HTTP headers are
Every web response starts with a status line and a list of headers: short name and value pairs that tell the browser how to handle the page. They cover things like the content type, caching, cookies, compression, redirects and security settings.
We send an ordinary request, follow any redirects, and show every header of the final response in the order it arrived. You can also open the headers of each redirect on the way.
Useful headers to look at
Cache-Control,AgeandETag: how long browsers and caches may keep the page.Content-TypeandContent-Encoding: what the response is and whether it is compressed.Set-Cookie: cookies the site sets. We show their names and settings but hide their values.ServerandVia: the server software or proxies, if the site chooses to say.
For security headers with explanations, use the Security Header Checker.
Frequently asked questions
Why are cookie values hidden?
Cookies the site sets for our check are of no use to you, and some look like session tokens. We show each cookie's name and settings (Secure, HttpOnly, SameSite and so on) and the length of its value, but never the value itself.
Why do I see different headers in my browser?
Sites can vary headers by browser, location, language, cookies or login state, and content delivery networks may answer from different servers. We send a plain request with no cookies, identified as ToolSiteCheck.
Do you use GET or HEAD?
GET, as a browser does, because some servers answer HEAD requests differently. We read at most 64 KB of the page and then stop; the content is not stored or shown.
What do the timings mean?
DNS is the time to look up the address, connect is the time to open the connection, TLS is the secure handshake, and first byte is when the server started to answer.
Related tools
-
Security Header Checker
Check which browser security headers a website sends (HSTS, CSP, X-Content-Type-Options, Referrer-Policy and Permissions-Policy) and what they do.
-
Redirect Checker
Follow a web address through every redirect, with the status code, destination and timing of each hop.
-
Website Down Checker
Check whether a website is responding right now, from our server: status, response time, redirects, IP addresses and HTTPS.
-
SSL Certificate Checker
Check whether a site's HTTPS certificate is valid and trusted, which names it covers, and when it expires.
-
DNS Lookup
Look up the DNS records published for a domain, one type or all common types at once, or the reverse DNS name of an IP address.
-
MX Lookup
See which mail servers receive email for a domain, in priority order, with each server's addresses.
-
SPF Checker
Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.
-
DMARC Checker
Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.
-
Website Health Check
Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.