Free HTTP headers checker

Inspect the HTTP response headers returned by a public webpage.

See public response metadata from the final browser document, including content type, caching, server/CDN hints and security headers.

Free · No signup required · Live public website check

What this tool checks

Response metadata from the final document

Content headers

Inspect fields such as Content-Type and Content-Encoding when the server returns them.

Caching headers

Review Cache-Control, Age, ETag, Last-Modified and related caching metadata when present.

Server and CDN hints

See public Server, Via and cache-layer response headers when the endpoint exposes them.

Security headers

Keep HSTS, CSP, X-Frame-Options and other security headers in the same response view.

SEO-relevant headers

Inspect public fields such as X-Robots-Tag when they are returned by the final response.

Final response context

Keep the headers next to final status, final URL, redirects and browser timing.

Interpret the result

HTTP headers describe how browsers, caches and intermediaries should handle the response.

Response headers can control content type, caching, compression, security policy, CORS and crawler behavior. They are often essential when debugging CDN configuration, stale content or unexpected browser behavior.

SiteState intentionally omits credential and cookie response fields such as Set-Cookie and authentication challenge headers from the public report. The tool is therefore a broad public-header inspector, not an unfiltered packet dump.

Methodology

SiteState captures final-document response headers observed by Chromium and exposes a sanitized public list. Cookie/authentication-related response headers are excluded and values are length-limited.

FAQ

Common questions about this website check

What HTTP headers does SiteState show?

The tool shows sanitized public response headers from the final main document, including common content, caching, server/CDN, crawler and security metadata when present.

Does it show Set-Cookie?

No. SiteState excludes cookie and authentication-related response headers from the public diagnostic output.

Does the tool follow redirects?

Yes. The header list belongs to the final main document after browser navigation completes.

How is this different from the Security Headers Checker?

The HTTP Headers Checker shows broader response metadata. The Security Headers Checker focuses specifically on a curated six-header browser-security baseline.

Continuous website state

Need ongoing history? Website monitoring turns one-off health checks into continuous state, incidents and change detection. Website monitoring.

A one-off check tells you what is happening now.

SiteState continuous monitoring keeps watching and builds history for changes, incidents and regressions.