HTTP Response Headers Checker
Raw headers, cache directives and security headers analysis.
- Runs in your browser
- Free, no signup
Returned Headers
| Header Name | Value | Copy |
|---|
Security-Related Headers Analysis
This overview checks for common web hardening headers. These indicators are strictly informational and do not represent a vulnerability assessment.
Raw HTTP Response Headers
Requests originate from our server with SSRF safeguards. Header values are not stored.
HTTP headers define caching policies, content types, server software, and browser security restrictions. Inspecting response headers is vital when debugging caching issues, CORS policies, or verifying that security directives are actively delivered.
ToolDuck retrieves headers using lightweight HEAD/GET requests, formats standard headers into clean tables, runs an informational security headers check, and lets you copy or download the raw output.
How to use this tool
- Paste any public HTTP or HTTPS URL into the input field.
- Click Check Headers to inspect the response.
- Review standard headers, examine security header presence, and click Copy Headers or Download Headers to save the output.
Essential web security headers
Strict-Transport-Security (HSTS) prevents downgrade attacks by instructing browsers to exclusively use HTTPS. Content-Security-Policy (CSP) mitigates Cross-Site Scripting (XSS) by whitelisting trusted script origins. X-Frame-Options prevents clickjacking by governing iframe embedding.
Our security analysis highlights whether these headers are active. We report these directives informationally without claiming a website is fully secure or vulnerable based on headers alone.
Cache-Control, ETag, and CDN behavior
Cache-Control (e.g. max-age=31536000, immutable or no-store) tells browsers and edge CDNs how long an asset may be reused without requesting the origin server again. ETags provide unique resource fingerprints for 304 Not Modified validation.
Inspecting these headers helps you diagnose why updated stylesheets or images are not appearing for your visitors.
Frequently asked questions
Can I download the raw headers as a file?
Yes. Click Download Headers to save the complete response header block as a .txt file.
Are request bodies or credentials transmitted?
No. Only standard GET/HEAD headers are requested. No cookies, authentication tokens, or private credentials are included.