Network Tools

HTTP Response Headers Checker

Raw headers, cache directives and security headers analysis.

  • Runs in your browser
  • Free, no signup

Examples: example.com • cloudflare.com • github.com

Accurate reporting: Only headers actually transmitted by the destination server in response to a standard request are shown. We do not invent missing headers or alter returned values.

Requests originate from our server with SSRF safeguards. Header values are not stored.

HTTP headers define caching policies, content types, server software, and browser security restrictions. Inspecting response headers is vital when debugging caching issues, CORS policies, or verifying that security directives are actively delivered.

ToolDuck retrieves headers using lightweight HEAD/GET requests, formats standard headers into clean tables, runs an informational security headers check, and lets you copy or download the raw output.

How to use this tool

  1. Paste any public HTTP or HTTPS URL into the input field.
  2. Click Check Headers to inspect the response.
  3. Review standard headers, examine security header presence, and click Copy Headers or Download Headers to save the output.

Essential web security headers

Strict-Transport-Security (HSTS) prevents downgrade attacks by instructing browsers to exclusively use HTTPS. Content-Security-Policy (CSP) mitigates Cross-Site Scripting (XSS) by whitelisting trusted script origins. X-Frame-Options prevents clickjacking by governing iframe embedding.

Our security analysis highlights whether these headers are active. We report these directives informationally without claiming a website is fully secure or vulnerable based on headers alone.

Cache-Control, ETag, and CDN behavior

Cache-Control (e.g. max-age=31536000, immutable or no-store) tells browsers and edge CDNs how long an asset may be reused without requesting the origin server again. ETags provide unique resource fingerprints for 304 Not Modified validation.

Inspecting these headers helps you diagnose why updated stylesheets or images are not appearing for your visitors.

Frequently asked questions

Can I download the raw headers as a file?

Yes. Click Download Headers to save the complete response header block as a .txt file.

Are request bodies or credentials transmitted?

No. Only standard GET/HEAD headers are requested. No cookies, authentication tokens, or private credentials are included.