What HTTP Headers Checker checks
- Response headers — all the headers the server returns, including at every redirect step.
- Security headers — HSTS, Content-Security-Policy, X-Content-Type-Options, frame protection, Referrer-Policy and Permissions-Policy with a grade from A to F.
- Version disclosure — whether the server gives away its own version through Server or X-Powered-By.
- Performance — compression (gzip, Brotli) and caching headers.
- SEO — X-Robots-Tag, the canonical address in the Link header and the response code.
- Cookies — whether they have the Secure, HttpOnly and SameSite flags.
The most important security headers
Headers that affect SEO
Some headers directly control search results. X-Robots-Tag: noindex forbids indexing a page just like meta robots, but also works for PDFs and images. The Link: <url>; rel="canonical" header gives the main address for non-HTML files. The response code decides whether a page gets into the index: 200 is normal, 301 carries signals over, 404 and 410 remove the page, and 5xx temporarily slow down crawling. Compression and caching shorten loading time, and a site’s speed is checked by the site speed check.
How to read the result
The security grade consists of six checks: HSTS and CSP give two points each, the rest one each. A grade of A means 7–8 points, B six, C four to five, D two to three, F fewer than two. It is a quick check that headers exist, not a full audit: it does not judge whether the CSP or Permissions-Policy itself is correct. If a CDN sits in front of the server, some headers are added by it. What happens after the switch to https is shown by Redirect Checker, and whether the page is blocked from the bot by Googlebot Checker.
Limits of the check
We make one GET request from our server and do not run JavaScript. Headers can depend on the User-Agent, country, cookies or authorization, so a visitor’s response sometimes differs. Sites behind bot protection may give us a challenge page instead of the real response.
What else StayIndexed can do
This page is a free tool from the StayIndexed service. In your account you can save a list of URLs, refresh the check in one click and see when the headers changed (also free), while the main job of the service is to track how your pages are doing in Google.
How much it costs
The check is free, both on this page and in your account. Tokens are used to pay for the other services: indexing, speed and backlinks cost 3 tokens per check. 30 tokens are credited at sign-up, no card required.
Frequently asked questions
How do I view a site’s HTTP headers?
Enter the page address in the form above: we will open it, follow the redirects and show all the server’s response headers. Headers are also visible in the browser’s developer tools on the Network tab.
What are HTTP headers?
They are service lines the server sends along with a page: the response code, content type, caching rules, security settings and much more. Browsers and search bots read them before the page itself.
Which security headers are essential?
At a minimum: Strict-Transport-Security for https, X-Content-Type-Options: nosniff, frame protection (X-Frame-Options or frame-ancestors) and Content-Security-Policy. Referrer-Policy and Permissions-Policy are also worth adding.
Do headers affect SEO?
Yes. X-Robots-Tag can block a page from indexing, the response code decides its fate in Google, and compression and caching speed up the site. A wrong header such as noindex can quietly remove pages from search.
Why hide the server version?
A Server or X-Powered-By header with a version number helps attackers find known vulnerabilities. Removing the header is not required, but hiding exact versions works for security.
How much does a headers check cost?
Nothing: the check is free both on this page and in your StayIndexed account. In your account you can save a list of URLs, refresh the check in one click and see the history of header changes.