HTTP Header Checker: Read Security Headers
Auditing corporate security headers needs the first response exactly as sent. This guide inspects headers without following redirects. Query only public URLs over standard ports, max six requests. Never query login-gated URLs.
Step by step
- Enter the full public page URL with scheme.
- Start the query; only the first response is shown.
- Find HSTS, CSP, and X-Content-Type-Options lines.
- Note missing values, inspect Location too.
- Wait after fixes, re-query.
Example scenario
A corporate blog fails a header scan. The homepage shows missing HSTS and report-only CSP. Output goes to developers; after the fix a re-check confirms headers. The next audit has fewer warnings.
Check your result
Read each header name and value. Note version-exposing headers. Query the Location target separately. Caches may serve older responses; wait and re-check.
Frequently asked questions
Why no post-redirect headers?
Only the first response is shown by design.
HSTS missing?
Define Strict-Transport-Security, raise max-age gradually.
Pages behind login?
No. Evaluate from a public page.
Different results?
CDN caching; wait and retry.
Open the tool: HTTP Header Checker →
Keep an original copy before processing your file. Examples are illustrative; results depend on your document.