↑↓ to move ↵ to open Esc to close Browse all tools

HTTP Header Checker

Enter a URL to follow its full redirect chain, see the status code and response headers of every hop, and grade the security headers of the final page.

Check a URL

Try

Our server requests the address once per hop and reads only the headers. Nothing is stored.

What the HTTP header checker shows

Before a browser shows a single pixel, the server answers with a status code and a block of response headers. They say whether the page exists, whether it moved, how long it may be cached, and which security rules the browser should apply. This HTTP header checker sends the request for you, follows every redirect by hand and lists each hop with its status code, address, server address and time, so a chain like http to https to www to the final page becomes visible.

It is the quickest way to answer questions like these: does the old URL really send a 301 to the new one after a relaunch, is there a redirect loop, why does Google index the wrong address, and does the site send HSTS and a Content Security Policy (CSP).

Status codes in a redirect chain

CodeMeaning
200 OKThe page loaded. The end of every healthy chain.
301 Moved PermanentlyThe page has a new address for good. Search engines move rankings to the target. Use it for http to https and old URLs.
302 FoundA temporary redirect. Search engines keep the old URL in the index. Fine for logins and short campaigns, wrong for a permanent move.
307 and 308Like 302 and 301, but the browser must keep the request method, which matters for forms and APIs.
404 Not FoundThe address does not exist. A redirect chain that ends here wastes every link pointing at it.
410 GoneRemoved on purpose. Search engines drop the page faster than with a 404.
5xxServer errors, like 500 or 503. The site is down or broken right now.

The security headers and the grade

The grade looks at six response headers of the final page. Each one closes a common gap, and most can be added in a few lines of server config, for example in an .htaccess file on Apache or with add_header on nginx.

HeaderPointsWhat it does
Strict-Transport-Security25Browsers use https only, for the time in max-age. At least 180 days.
Content-Security-Policy25Lists where scripts, styles and frames may come from. The strongest defense against XSS.
X-Content-Type-Options15nosniff stops browsers from guessing file types.
X-Frame-Options or frame-ancestors15Stops other sites from showing yours in a frame (clickjacking).
Referrer-Policy10Controls how much of your URLs other sites see when visitors click a link.
Permissions-Policy10Switches off camera, microphone, location and other features you do not use.

The checker also flags headers like Server or X-Powered-By when they reveal software versions, which helps attackers pick known holes. Certificates are not part of the grade; check them with the SSL checker, and find dead links on the final page with the broken link checker.

How to check redirects and headers

  1. 1Enter the address people start from. Type http:// in front to test the redirect to https.
  2. 2Read the chain from top to bottom: each line shows the status code and where it points next.
  3. 3Check the grade and open the headers of any hop. Copy the result for your developer or hosting support.

Frequently asked questions

How many redirects are too many?

One is normal, for example http to https or the bare domain to www. Two can happen. Every extra hop adds a round trip, often 100 to 300 milliseconds on a phone, and Google follows at most 10 before it gives up. Point old links straight at the final address so each URL needs at most one redirect.

Should I use 301 or 302?

Use 301 (or 308) when a page has moved for good, such as after a relaunch or the switch to https. Use 302 (or 307) only when the old address will come back, for example during maintenance. A 302 left in place for a permanent move can keep the old URL in search results for months.

How is the security grade worked out?

Six headers earn points: HSTS and Content-Security-Policy 25 each, X-Content-Type-Options and clickjacking protection 15 each, Referrer-Policy and Permissions-Policy 10 each. A weak value earns part of the points. 95 or more is A+, 80 is A, 65 is B, 50 is C, 30 is D, below that F. The grade covers headers only, not the rest of the site’s security.

Why do I see different headers in my browser?

Servers can answer differently depending on the user agent, the language, cookies or the visitor’s country. This checker sends a plain request without cookies, as a crawler would, from a server in Germany. A CDN can also serve a cached copy with other headers than your origin server.

Can it check an http address?

Yes. Type the address with http:// in front to see whether the site redirects to https, which every site should do. Without a scheme the checker starts with https.