Security headers
HSTS passes. Missing CSP fails; missing framing protection, Referrer-Policy, nosniff, Permissions-Policy, and COOP are warnings. Missing COEP is informational.
Free, no signup. See the headers browsers and crawlers receive: every redirect hop, separate security and SEO grades, edge fingerprints, compression, and an honest HTTP/3 signal.
This makes two user-triggered requests for one URL from Cloudflare infrastructure. It compares user-agent responses, not verified crawler behavior or crawler IP access.
The report compares the final response headers from two independent checks.
Checks run from our server; we fetch the URL you enter and don't keep the results. Complete response header maps are returned to your browser. Repeating the same URL and user-agent within about ten minutes may reuse a short-lived edge cache. Anonymous run-level outcome counters may be used for aggregate research; URLs, domains, IPs, and identifiers are never included, and no statistic is released below 100 runs.
Frequency is calculated in this browser from the live final responses in this run. It is not a global popularity dataset.
| Header | Responses | Frequency | Registry status |
|---|
Illustrative example — exact grading for the fixed header map below
HTTP/2 200
strict-transport-security: max-age=31536000
cache-control: public, max-age=3600
etag: "abc123"HSTS passes. Missing CSP fails; missing framing protection, Referrer-Policy, nosniff, Permissions-Policy, and COOP are warnings. Missing COEP is informational.
Cache-Control and ETag pass. Missing X-Robots-Tag, Link canonical, and Vary are informational in this HTTP-only grade.
The displayed HTTP/2 line is illustrative input only: the live Worker cannot expose the negotiated HTTP version.
+ saves the current site or page. Use ☆ beside any saved site, page, or list to favorite it. Recent check history appears below.
Target filled from your local choices.
Saved targets, named lists, and recent check summaries remain only in this browser.
A bounded server-side checker sends the selected user-agent, records each redirect response without hiding intermediate headers, and returns normalized header maps and timings. Browser-side functions grade the final response, parse Link headers, inspect compression and protocol advertisements, identify a small set of edge fingerprints, produce a curl-style view, and diff an optional second final response. The small batch mode counts fields only across the final responses fetched in that run and labels names from a local status-preserving snapshot of the IANA HTTP Field Name Registry.
The report cannot expose negotiated HTTP version, TLS certificate details, private origin infrastructure, or headers added only inside a user's network. The Fetch Headers API may combine repeated field lines: parsed combined values are assessed, but the original field-line order and boundaries cannot be reconstructed. User-agent strings originate from a Cloudflare datacenter, not verified crawler IP ranges. It does not inspect HTML metadata, application security, or whether a 200 body is correct.
Not exactly. The Worker Fetch Headers API exposes a normalized, potentially combined value. The checker parses and assesses that combined value, but it cannot reconstruct the original order or boundaries of repeated field lines.
Workers do not expose the negotiated HTTP version. The tool only reports when Alt-Svc advertises HTTP/3; that is not proof this request used HTTP/3.
Sites can vary headers by user-agent. This sends the selected user-agent string from a Cloudflare datacenter, not from a verified crawler IP range.
No. The URL is fetched to build this report and a short-lived edge cache may reuse the same URL and user-agent response for about ten minutes.
No. The grade covers a defined set of public response headers. It does not test application vulnerabilities, authentication, server configuration, dependency risk, or whether a policy works correctly for the application.
No. It evaluates HTTP-level signals such as X-Robots-Tag and Link headers. Page-level canonical and robots elements require an HTML-aware checker.
Upvote what you want most. New ideas can be submitted from the floating Feedback menu; requests appear here once approved, and the most-wanted rise to the top.
You won't be emailed about that request anymore.
Loading…
New requests are reviewed before they appear here.
افحص كل HTTP استجابة رأس في واحد سلسلة إعادة التوجيه, مع الأمان و تحسين محركات البحث grades, CDN fingerprints, compression حقائق, واحد خام curl-style عرض, و واحد اختياري بيئة فرق.
مجاني, من دون تسجيل. انظر ال رؤوس متصفحات و زواحف receive: كل إعادة التوجيه قفزة, منفصل الأمان و تحسين محركات البحث grades, حافة fingerprints, compression, و واحد صادق HTTP/3 إشارة.
واحد محدود server-side فاحص يرسل ال مختار user-agent, سجلات كل إعادة التوجيه استجابة من دون hiding intermediate رؤوس, و يعيد normalized رأس خرائط و timings. Browser-side دوال درجة ال نهائي استجابة, حلّل رابط رؤوس, افحص compression و بروتوكول advertisements, حدّد واحد صغير مجموعة من حافة fingerprints, ينتج واحد curl-style عرض, و فرق واحد اختياري الثاني نهائي استجابة. ال صغير دفعة وضع أعداد حقول فقط عبر ال نهائي استجابات مجلوب في ذلك شغّل و تسميات أسماء من واحد محلي status-preserving لقطة من ال IANA HTTP حقل اسم سجل.
ليس بالضبط. ال Worker جلب رؤوس API يكشف واحد normalized, potentially المُجمَّع قيمة. ال فاحص يحلل و assesses ذلك المُجمَّع قيمة, لكن إنه لا يمكن reconstruct ال أصلي ترتيب أو boundaries من متكرر حقل أسطر.
Workers يفعل ليس يكشف ال متفاوض عليه HTTP إصدار. ال الأداة فقط يبلّغ عندما Alt-Svc advertises HTTP/3; ذلك هو ليس دليل هذا طلب مستخدم HTTP/3.
مواقع يمكن يختلف رؤوس بواسطة user-agent. هذا يرسل ال مختار user-agent string من واحد Cloudflare datacenter, ليس من واحد تم التحقّق منه زاحف IP نطاق.
لا. ال عنوان URL هو مجلوب إلى بناء هذا تقرير و واحد قصير العمر حافة ذاكرة مؤقتة قد إعادة استخدام ال نفس عنوان URL و user-agent استجابة من أجل حول عشرة دقائق.
لا. ال درجة يغطي واحد محدّد مجموعة من عام استجابة رؤوس. إنه يفعل ليس اختبار تطبيق vulnerabilities, مصادقة, خادم إعداد, اعتمادية مخاطر, أو ما إذا واحد سياسة يعمل بصورة صحيحة من أجل ال تطبيق.
لا. إنه يقيّم HTTP-level إشارات مثل باعتباره X-Robots-Tag و رابط رؤوس. على مستوى الصفحة أساسي و Robots عناصر يتطلب واحد HTML-aware فاحص.