HTTP Headers Checker

See every HTTP response header plus a security-header grade.

What are HTTP response headers?

HTTP response headers are key–value lines a server sends before the page content. They control caching, compression, security, cookies, redirects and indexing — for example Cache-Control, Content-Type, Strict-Transport-Security and X-Robots-Tag.

Headers that matter for SEO

  • X-Robots-Tag — works like a robots meta tag but at the HTTP level. X-Robots-Tag: noindex keeps a page (or a PDF) out of Google even if the HTML has no meta tag. Check this first when a page will not index.
  • Link: <…>; rel="canonical" — sets a canonical URL in the header, useful for PDFs and other non-HTML files.
  • Location — the target of a 301/302 redirect.
  • Content-Type — should be text/html; charset=utf-8 for pages. A wrong type or charset can garble text in search snippets.
  • Vary — tells caches when a response differs by device or language (for example Vary: Accept-Encoding).

Headers that matter for speed

  • Content-Encoding — br (Brotli) or gzip compress text 70–90 %. Missing compression is a quick Core Web Vitals win.
  • Cache-Control — public, max-age=31536000, immutable for versioned assets; short or no-cache for HTML that changes.
  • ETag / Last-Modified — allow cheap revalidation with 304 Not Modified responses.
  • Server-Timing and CF-Cache-Status — show backend time and whether a CDN served the response from cache.

Security headers and the grade

The grade counts six widely recommended security headers:

HeaderWhat it preventsTypical value
Strict-Transport-SecurityHTTPS downgrade attacksmax-age=31536000; includeSubDomains
Content-Security-PolicyCross-site scripting and data injectionSite-specific allow-list
X-Content-Type-OptionsMIME-type sniffingnosniff
X-Frame-OptionsClickjackingSAMEORIGIN (or CSP frame-ancestors)
Referrer-PolicyLeaking full URLs to other sitesstrict-origin-when-cross-origin
Permissions-PolicyUnwanted camera, mic or location accesscamera=(), microphone=()

Six present scores A+; each missing header lowers the grade. Security headers are not a direct ranking factor, but HTTPS is, and a hacked site loses rankings fast.

Adding headers

On Apache use Header always set X-Content-Type-Options "nosniff" in .htaccess; on nginx use add_header X-Content-Type-Options "nosniff" always;; on Cloudflare use Transform Rules. Re-run this checker after deploying.

Related: check where a URL redirects with the Redirect Checker, or verify a page's canonical with the Canonical URL Checker.

Frequently asked questions

How can I see the HTTP headers of a website?

Enter the URL and click Check now. This tool requests the page and lists every response header, the status code, server and response time.

What does X-Robots-Tag: noindex mean?

It tells search engines not to index the response. If a page will not appear in Google, check for this header as well as the robots meta tag.

Are security headers a Google ranking factor?

Not directly. HTTPS is a light ranking signal, and security headers protect your site from attacks that can lead to penalties or lost traffic.

Why are some headers different from what my browser shows?

Responses can vary by user agent, cookies, location or CDN cache state. We request the page as a normal desktop browser without cookies.

What is a good Cache-Control header for HTML?

For pages that change often, use a short max-age or no-cache so visitors get fresh content. Use long max-age only for versioned static files.