HTTP headers

Check security headers, cookies and caching.

Enter a domain or URL. Defaults to https://.

About this scan

Checks the final response after up to five redirects: security, cookies, caching and server information. Does not run JavaScript or send cookies.

Anyone with the result link can view the report. Reports expire after seven days. Query values and sensitive headers are redacted.

A snapshot, not a security guarantee.

From scan to solution

Understand what your headers are telling you

HTTP response headers control how browsers load a page, store its content and handle cookies. Use HeaderScan to inspect the final response, then use these guides to turn a missing header or an unexpected value into a focused change. Start with the policy that affects your page, and check the response again after deploying it.

A few useful answers

Frequently asked questions

Which HTTP response does HeaderScan inspect?

HeaderScan follows up to five redirects and analyzes the final response. The report covers security headers, cookies, caching and server information on that response. If the URL ends on a login screen or CDN challenge, the findings describe that page.

Does a missing security header mean my site is unsafe?

A missing header is a reason to review the intended browser policy. It is not proof of an exploitable vulnerability. Check whether the policy applies to your page and test changes against real user journeys. A high score is not a security guarantee.

HTTP security headers: what to check first
Why are my login cookies missing from the report?

The scan does not sign in, send cookies or run JavaScript. It only sees cookies set in the final response headers. Cookies created after authentication or by a script need a separate check in your own browser session.

Secure, HttpOnly and SameSite cookies explained
What is the difference between no-cache and no-store?

no-cache permits storage but requires validation before reuse. no-store tells caches not to store the response. Choose the policy according to the content: a public asset and a sensitive account page have different caching requirements.

Cache-Control explained: no-cache, no-store and private
Why do the reported headers differ from my server configuration?

The scan sees the public response after any redirects. A CDN, proxy, route-specific setting or error handler may add or replace headers. Compare the final URL with the page you intended to test, then check each layer that supplies that response.