Headers that matter for SEO
- X-Robots-Tag — works like a robots meta tag but at the HTTP level.
X-Robots-Tag: noindexkeeps a page (or a PDF) out of Google even if the HTML has no meta tag. Check this first when a page will not index. - Link: <…>; rel="canonical" — sets a canonical URL in the header, useful for PDFs and other non-HTML files.
- Location — the target of a 301/302 redirect.
- Content-Type — should be
text/html; charset=utf-8for pages. A wrong type or charset can garble text in search snippets. - Vary — tells caches when a response differs by device or language (for example
Vary: Accept-Encoding).
Headers that matter for speed
- Content-Encoding —
br(Brotli) orgzipcompress text 70–90 %. Missing compression is a quick Core Web Vitals win. - Cache-Control —
public, max-age=31536000, immutablefor versioned assets; short orno-cachefor HTML that changes. - ETag / Last-Modified — allow cheap revalidation with 304 Not Modified responses.
- Server-Timing and CF-Cache-Status — show backend time and whether a CDN served the response from cache.
Security headers and the grade
The grade counts six widely recommended security headers:
| Header | What it prevents | Typical value |
|---|---|---|
| Strict-Transport-Security | HTTPS downgrade attacks | max-age=31536000; includeSubDomains |
| Content-Security-Policy | Cross-site scripting and data injection | Site-specific allow-list |
| X-Content-Type-Options | MIME-type sniffing | nosniff |
| X-Frame-Options | Clickjacking | SAMEORIGIN (or CSP frame-ancestors) |
| Referrer-Policy | Leaking full URLs to other sites | strict-origin-when-cross-origin |
| Permissions-Policy | Unwanted camera, mic or location access | camera=(), microphone=() |
Six present scores A+; each missing header lowers the grade. Security headers are not a direct ranking factor, but HTTPS is, and a hacked site loses rankings fast.
Adding headers
On Apache use Header always set X-Content-Type-Options "nosniff" in .htaccess; on nginx use add_header X-Content-Type-Options "nosniff" always;; on Cloudflare use Transform Rules. Re-run this checker after deploying.
Related: check where a URL redirects with the Redirect Checker, or verify a page's canonical with the Canonical URL Checker.
Frequently asked questions
How can I see the HTTP headers of a website?
Enter the URL and click Check now. This tool requests the page and lists every response header, the status code, server and response time.
What does X-Robots-Tag: noindex mean?
It tells search engines not to index the response. If a page will not appear in Google, check for this header as well as the robots meta tag.
Are security headers a Google ranking factor?
Not directly. HTTPS is a light ranking signal, and security headers protect your site from attacks that can lead to penalties or lost traffic.
Why are some headers different from what my browser shows?
Responses can vary by user agent, cookies, location or CDN cache state. We request the page as a normal desktop browser without cookies.
What is a good Cache-Control header for HTML?
For pages that change often, use a short max-age or no-cache so visitors get fresh content. Use long max-age only for versioned static files.

