Header Checker
Inspect HTTP response headers returned by the web server.
In practice
Findings to confirm in Header Checker
- You did not claim HSTS preload from this row.
- You did not say the origin is Cloudflare.
- You did not copy max-age=3600 into a config.
- You treated the date as local clock time.
- A real response dump is the source for header work.
In practice
How a Header Checker finding reads
Input
Type https://example.com. The table shows HTTP/2 200 OK, Server cloudflare, today’s date, HSTS with preload, X-Frame-Options SAMEORIGIN, and Content-Encoding br. None of those lines were read from example.com.
What you should see
Request the URL and inspect response headers. Use that dump. The preload token on this page is not evidence the domain is on the HSTS preload list.
From the form
Language in the Header Checker report
| Term | Meaning |
|---|---|
| HSTS | Strict-Transport-Security. The sample includes includeSubDomains and preload. |
| X-Frame-Options | A framing policy. The sample says SAMEORIGIN. |
| nosniff | X-Content-Type-Options. The sample includes it. |
| Content-Encoding | Compression such as br. The sample prints br without negotiating it. |
| Cache-Control | Freshness rules. The sample prints public, max-age=3600. |
On this tool
Severity, scope, and what Header Checker skipped
Response headers are key-value lines a server sends before the body. Security headers such as Strict-Transport-Security and X-Frame-Options tell the browser how to treat the page. This table shows that shape without making the request.
Response headers are the lines before the body. Security headers such as Strict-Transport-Security and X-Frame-Options tell the browser how to treat the page. This table shows that shape. The Date line uses the current time so it looks fresh, but it was not sent by the server.
Status line is one of the values Header Checker puts on screen. The first line names the protocol and the code. The sample says HTTP/2 200 OK. The live response might be HTTP/1.1 or a 301.
Read Server on its own before you mix it with the other rows. Server names the software or the proxy. The sample says cloudflare. The site may not be on Cloudflare.
Strict-Transport-Security answers a narrower question than the headline number. HSTS tells the browser to stay on HTTPS. The sample value is max-age=31536000; includeSubDomains; preload. Do not say the site is preloaded because this row exists.
Treat X-Frame-Options as a label with a specific job. This header limits framing. The sample says SAMEORIGIN. The live page might use CSP frame-ancestors instead, or nothing.
The Cache-Control and encoding line is worth a full stop. Cache-Control sets freshness. Content-Encoding names compression. The sample says public, max-age=3600 and br. Those are not the live cache policy or the live encoding.
Content-Encoding br, Cache-Control max-age=3600, and X-Content-Type-Options nosniff are in the fixture. Seeing them here is not a pass for the live response.
If you remember one sequence from Header Checker, remember the fields in the order they change a decision. Status line matters because The first line names the protocol and the code. In practice, The sample says HTTP/2 200 OK. The mistake to avoid is this: The live response might be HTTP/1.1 or a 301. Server matters because Server names the software or the proxy. In practice, The sample says cloudflare. The mistake to avoid is this: The site may not be on Cloudflare. Strict-Transport-Security matters because HSTS tells the browser to stay on HTTPS. In practice, The sample value is max-age=31536000; includeSubDomains; preload. The mistake to avoid is this: Do not say the site is preloaded because this row exists. X-Frame-Options matters because This header limits framing. In practice, The sample says SAMEORIGIN. The mistake to avoid is this: The live page might use CSP frame-ancestors instead, or nothing. Cache-Control and encoding matters because Cache-Control sets freshness. Content-Encoding names compression. In practice, The sample says public, max-age=3600 and br. The mistake to avoid is this: Those are not the live cache policy or the live encoding. After that, the checks are simple. You did not claim HSTS preload from this row. You did not say the origin is Cloudflare. You did not copy max-age=3600 into a config. You treated the date as local clock time. A real response dump is the source for header work.
The worked example for Header Checker, read as one scene, is this. Type https://example.com. The table shows HTTP/2 200 OK, Server cloudflare, today’s date, HSTS with preload, X-Frame-Options SAMEORIGIN, and Content-Encoding br. None of those lines were read from example.com. Request the URL and inspect response headers. Use that dump. The preload token on this page is not evidence the domain is on the HSTS preload list.
Final notes for Header Checker, written as decisions rather than as a table. When Status line is in front of you, decide using this: The first line names the protocol and the code. The live response might be HTTP/1.1 or a 301. When Server is in front of you, decide using this: Server names the software or the proxy. The site may not be on Cloudflare. When Strict-Transport-Security is in front of you, decide using this: HSTS tells the browser to stay on HTTPS. Do not say the site is preloaded because this row exists. When X-Frame-Options is in front of you, decide using this: This header limits framing. The live page might use CSP frame-ancestors instead, or nothing. When Cache-Control and encoding is in front of you, decide using this: Cache-Control sets freshness. Content-Encoding names compression. Those are not the live cache policy or the live encoding. Then apply the checks without skipping one. You did not claim HSTS preload from this row. You did not say the origin is Cloudflare. You did not copy max-age=3600 into a config. You treated the date as local clock time. A real response dump is the source for header work.
Keep Header Checker as this step only. When the job moves on, the SEO Audit Tool is the next page: SEO Audit Tool sends the URL you enter to the iSkills server, which fetches that page and returns on-page checks plus a PageSpeed request. The Page Size Checker covers a different piece of the same work: Page Size Checker asks for a URL and then shows a total kilobyte figure plus a split across HTML, images, scripts, and CSS.
Where Header Checker fits
Header Checker asks for a URL and lists response headers, including a few security header names. It is a sample header table. The URL is not requested, so the values are not the live response from that host.
The header table is a sample. This page does not request the URL. The rows are a fixed set, including a Cloudflare server name and a strict-transport-security policy the host may not send.
Header Checker in order
Enter a URL.
Run the check. The host is not contacted.
Read the header name and value rows, including the security names.
Compare with a real response before you claim a header is present or missing.
What Header Checker returns
- The table pairs a field with a value, which is how a header dump looks.
- Security names are included so you know what to look for later.
- The host is not contacted, so you cannot break anything by typing a URL.
Easy to misread Header Checker
Claiming HSTS preload
preload in the sample is text. Preload is a list you submit to, not a row on this page.
Saying the origin is Cloudflare
Server: cloudflare is hard-coded.
Copying max-age=3600 into a config
That cache policy is the fixture.
Ignoring a missing header on the live site
Absence on this table means nothing, because the table never loads the site.
On this tool
Questions after a Header Checker run
Does Header Checker request the URL?
No. The rows are a fixed sample. The date is the current time, not a server date.
Which security headers appear?
Strict-Transport-Security, X-Frame-Options, and X-Content-Type-Options are on the fixture.
Is the site on Cloudflare?
Not according to this table. Server cloudflare is written in the sample.
How do I read live headers?
Request the URL and inspect the response headers.