Web tool / 07

HTTP Headers Checker

Read a URL’s final response headers and spot commonly used browser security policies.

HTTP Headers Checker: TOEA follows HTTP redirects and lists the final response headers, highlighting Content Security Policy, HSTS, framing, referrer, permissions, and MIME-sniffing controls when present. Processed securely on demand.

Category
Web tools
Runs
On TOEA's server
Cost
Free · no sign-up
Availability
Ready to use
Response header deskSafe public URL check

Reads final response headers and highlights common browser security policies.

Sensible values for the security headers

Strict-Transport-Security: max-age=31536000; includeSubDomains makes browsers use HTTPS for a year; add includeSubDomains only when every subdomain serves HTTPS with a valid certificate, which the SSL checker confirms name by name. X-Content-Type-Options: nosniff has one valid value. Referrer-Policy: strict-origin-when-cross-origin is the browser default and sends other sites only your domain. X-Frame-Options: DENY stops other sites framing your pages; the modern equivalent is frame-ancestors 'none' in the Content Security Policy.

Introducing a Content Security Policy

A CSP lists where scripts, styles, images, and frames may load from, and a strict one breaks any page that loads something it does not list. Roll it out as Content-Security-Policy-Report-Only first: browsers report violations in the console, or to an endpoint you name, without blocking anything. Tighten the policy until the reports stop, then switch to the enforcing header. Headers set by a CDN or proxy appear here alongside your server's own, so a header you removed may still be added upstream.

How to use it

  1. Enter a public page or resource URL.
  2. Choose Read headers.
  3. Review the complete header ledger and the common security-policy summary.

Privacy & limitations

The URL is checked through TOEA’s API and is not saved. Set-Cookie and proxy authentication header values are redacted from the result.

Related tools

Frequently asked questions

Does a missing header always mean a vulnerability?

No. The right policies depend on the content and deployment. The summary is an inventory, not a security certification.

Which response is shown after redirects?

The ledger shows headers from the final response.

Free tool · runs on toea's server · no account required