IP Number Tracker
Open menu

HTTP Header Checker

Easily check status codes, response headers and redirect chains for up to 10 URLs at once, as a browser or as a search engine bot.

Identifies itself honestly as IP Number Tracker. Checked from our server over HTTP and HTTPS (ports 80 and 443). Public websites only.

Enter one or more URLs to see their status codes and headers.

Put one address on each line, up to 10. You'll get the redirect chain and every response header, explained.

What an HTTP header checker shows you

Before a web page reaches your browser, the server sends a block of headers: small name and value pairs that say what the content is, how long it can be kept, where to go next, and which security rules to follow. You never see them while browsing, but they decide a lot about how a site behaves.

A header checker fetches them for you. People use it to debug caching, to confirm a redirect, to see whether a site sends its security headers, to find out why a page won't index, and to compare what a site sends to a desktop browser, a phone and a search crawler.

How this HTTP header checker works

Put up to ten addresses in the box, one per line, and press Check status. For each one we send a normal web request from our server and follow any redirects, up to eight steps, recording the status code, the response headers and the time every step took. The table shows each address with a coloured chip for every status code on the way, so a 301 followed by a 200 is obvious at a glance.

Click a row to open it. You get a summary of every step (status, scheme, host, path and time) and a timeline with the full response headers of each hop. Tick Explain each header for a one-line meaning under every header, and open the security, caching and cookie panels on the final response for a quick health check. You can filter the table, search it, and download everything as a CSV.

Under Settings you can switch between GET and HEAD, or stop following redirects to see the redirect response itself. The User Agent menu lets you request the page as a desktop or mobile browser, as a search engine bot such as Googlebot or Bingbot, or as a social crawler, to see whether a site answers them differently. Only public websites on ports 80 and 443 can be checked, and we speak HTTP/1.1.

The canonical domain check

Most sites can be reached four ways: http://example.com, https://example.com, http://www.example.com and https://www.example.com. They should all end up on one address. If they don't, search engines may treat them as separate sites and split the ranking between them. Tick Canonical domain check and we test all four forms of the first address you enter, then tell you whether they land in the same place.

The security headers worth having

Six headers do most of the work. Here is what each protects against and a sensible starting value. A missing one isn't always a flaw, but you should know it's missing.

HeaderProtects againstTypical value
Strict-Transport-SecurityDowngrade to plain HTTPmax-age=31536000; includeSubDomains
Content-Security-PolicyInjected scripts (XSS)default-src 'self'; frame-ancestors 'self'
X-Frame-OptionsClickjackingSAMEORIGIN
X-Content-Type-OptionsMIME sniffingnosniff
Referrer-PolicyLeaking page addresses to other sitesstrict-origin-when-cross-origin
Permissions-PolicyUnwanted browser featurescamera=(), microphone=(), geolocation=()

The Content-Security-Policy is the powerful one and the easiest to get wrong. A strict policy can block scripts and styles your site depends on, so start with Content-Security-Policy-Report-Only, watch what it would have blocked, then enforce it. HSTS also deserves caution: once a browser has seen it, it refuses HTTP for the whole max-age, so make sure every subdomain works over HTTPS before adding includeSubDomains.

How the security grade is worked out

Each of the six headers is scored as good, could be better, or missing, and the Content-Security-Policy and HSTS count the most. A server that announces an exact software version, or a framework in X-Powered-By, loses a few points. The total becomes a letter. It's a quick health check of what the headers say, not a security audit: a site with a perfect grade can still have vulnerable code, and one with a poor grade may be perfectly safe for what it does.

Caching headers, in plain English

Caching headers decide whether visitors download a file again or reuse a copy. When a site feels slow, or a change doesn't appear, this is the first place to look. Cache-Control is the one that matters:

DirectiveWhat it does
max-age=NBrowsers may reuse the response for N seconds without asking the server.
s-maxage=NThe same for shared caches such as a CDN. It overrides max-age there.
no-cacheCaches may keep a copy, but must check with the server before using it.
no-storeDon't keep a copy at all. Used for private or sensitive pages.
public / privateWhether shared caches may store it, or only the visitor's own browser.
immutableThe file will never change, so there's no need to re-check it. Used for fingerprinted assets.
stale-while-revalidate=NA stale copy may be served for N seconds while a fresh one is fetched in the background.

ETag and Last-Modified let a browser ask “has this changed?” and receive a tiny 304 answer instead of the whole file. Vary tells caches which request headers change the response, so a compressed copy isn't served to a client that can't read it. A CDN's own headers, such as cf-cache-status or x-cache, tell you whether the response came from the cache or from the origin.

Redirect headers and the chain behind a URL

A redirect is a response with a status of 301, 302, 303, 307 or 308 and a Location header saying where to go next. The chain matters because every step is a round trip and each one can carry its own headers. When a link ends up somewhere unexpected, click through the steps above and read each response. For the status codes and timing of the same chain, use the website status checker.

CORS headers

If a browser console says a request was “blocked by CORS policy”, the answer is in the response headers of the site being called. Look for Access-Control-Allow-Origin: it must name your site or be *. If the request sends cookies, the server also needs Access-Control-Allow-Credentials: true and a specific origin, because a wildcard isn't allowed alongside credentials. The checker shows all the CORS headers together so you can see what the server really sends.

Cookie flags

Cookies arrive in Set-Cookie headers. Three flags do most of the protecting. Secure keeps the cookie off plain HTTP. HttpOnly hides it from page scripts, which limits what a stolen script can take. SameSite controls whether it is sent on requests from other sites, which is the main defence against cross-site request forgery. Login and session cookies should have all three. We show each cookie's name and flags but never its value.

Headers that give away too much

Server: nginx/1.18.0 or X-Powered-By: PHP/7.4 tells anyone exactly which software and version to look up flaws for. Hiding them isn't a defence on its own, but it removes free information. Typical fixes:

  • nginx: server_tokens off;
  • Apache: ServerTokens Prod and ServerSignature Off
  • PHP: expose_php = Off
  • Express: app.disable("x-powered-by")

Problems a header check helps you solve

  • A page won't appear in search results: look for a stray X-Robots-Tag: noindex.
  • A change isn't showing up: read Cache-Control and the CDN's cache status.
  • A download opens in the browser instead of saving, or the reverse: check Content-Type and Content-Disposition.
  • Text shows odd characters: the charset in Content-Type may be missing or wrong.
  • A script, font or API call fails in the browser: look at the CORS headers on that resource.
  • HTTPS isn't enforced: check for HSTS and for a 301 from HTTP to HTTPS on the first hop.
  • The site isn't responding at all: start with the status checker, then look at DNS and the port checker.

Check headers yourself

You can always do this from a terminal:

  • curl -I https://example.com sends a HEAD request and prints the headers.
  • curl -I -L https://example.com follows redirects and prints every hop.
  • curl -s -D - -o /dev/null https://example.com shows the headers of a normal GET request.
  • Windows PowerShell: (Invoke-WebRequest -Uri https://example.com -Method Head -UseBasicParsing).Headers
  • Browsers: the Network tab in developer tools shows both request and response headers for every request the page makes.

Your own machine shows your network's view, and ours gives an outside one. When they differ, a CDN, proxy or location rule is usually the reason.

Frequently asked questions

How do I check the HTTP headers of a website?

Enter the address above, one per line if you have several, and press Check status. Click a row to see every response header it returned, step by step through any redirects, with an optional plain-English note on each. For a one-liner on your own machine, curl -I followed by the address does the same job.

What are HTTP headers?

They are name and value pairs sent alongside a web page, before the page itself. Request headers describe what the browser wants and who it is. Response headers describe what the server is sending: its type, size, how long it can be cached, whether to redirect, and which security rules apply.

What is the difference between GET and HEAD here?

GET asks for the page the way a browser would. HEAD asks for the headers only, so nothing is downloaded. Most servers answer both the same, but some treat HEAD differently or don't support it, so if a result looks odd, try the other method.

Which security headers should every site have?

At minimum, Strict-Transport-Security on HTTPS sites, X-Content-Type-Options set to nosniff, a way to stop framing (X-Frame-Options or the CSP frame-ancestors directive), and a Referrer-Policy. A Content-Security-Policy gives the most protection but takes the most care to roll out, and Permissions-Policy is a useful extra.

How is the security grade worked out?

It's a simple weighted score over six common headers plus whether the server advertises its software version. Each one is good, could be better, or missing, and the percentage maps to a letter. It's a quick health check, not a security audit, and a site can be well protected in ways headers can't show.

Why does the site send different headers to different visitors?

Headers can depend on the visitor's browser, location, cookies, language and whether a cache already has the page. Switching the User Agent lets you see the desktop and mobile versions and how a site answers a crawler. Our own address is also not a home connection, so some sites reply differently to it.

Does it show the cookies a site sets?

It shows each cookie's name and its flags: Secure, HttpOnly, SameSite and expiry. The values are never shown or kept, since they can be session tokens.

Can I check many URLs at once?

Yes, up to ten per check. Put one address on each line. The results table shows every status code in each redirect chain, and you can filter by redirects or status code, search the list and download it as a CSV. The limit keeps the tool fair for everyone and avoids flooding any one site.

Why can't I check a port other than 80 or 443?

This tool is for websites, so it only requests pages on the standard HTTP and HTTPS ports. To find out whether another port accepts connections, the Port Checker tests one port at a time.

What does it mean when headers are missing from the response?

Either the site doesn't send them, or something in front of it, such as a proxy or CDN, strips or replaces them. Look at the Server and Via headers for clues. If you manage the site, add missing headers at the layer closest to the visitor, since that's the one that gets the last word.

Is it safe to use on any website?

It makes one ordinary request to a public site, the same as visiting it, and is rate-limited per visitor and per site. It never connects to private addresses. Please only check sites you own or have a reason to look at.

Check sites you own or have a reason to look at. Requests come from our server, are rate-limited, and only reach public websites.