Back to All Tools

HTTP Headers Inspector

Fetch HTTP response headers for any URL and get a security score based on the presence of essential security headers.

Key Security Headers

HeaderPurpose
Strict-Transport-SecurityForces HTTPS for a specified duration
Content-Security-PolicyRestricts sources for scripts, styles, images, etc.
X-Frame-OptionsPrevents your page from being embedded in an iframe (clickjacking)
X-Content-Type-OptionsStops browsers from guessing the content type
Referrer-PolicyControls what data is sent in the Referer header
Permissions-PolicyEnables/disables browser features like camera, microphone