← All tools

HTTP Header Checker

Read the HTTP headers your server sends with a page, follow its redirects, and check the headers that matter for search, caching and security.

What are HTTP headers?

When a browser or a search engine asks for a page, the server’s reply starts with a short block of technical lines before the page itself. These are the HTTP headers. They say whether the request succeeded, what kind of file is coming, whether it may be stored and for how long, whether it has moved, and how a browser should treat it.

Visitors never see them, but browsers and search engines act on them. A single header can keep a page out of Google, send every visitor to another address, or make a browser download the same files again on every visit.

How this test works

Our server asks for the address you enter, the way a browser does, and reads the headers of the reply. It doesn’t download the page’s content. If the reply is a redirect, it follows it, up to five steps, and shows each step with its status code. The headers in the report are those of the last reply, and they are shown exactly as the server sent them.

The request says it accepts compressed replies and identifies itself as SeoklaBot. Some servers send different headers to different visitors, so a browser or Googlebot may get a slightly different set.

What the report checks

Status and redirects. A working page answers with status 200. Codes starting with 3 are redirects, 4 means the page can’t be shown, and 5 means the server failed. One redirect is normal, for example from http to https. A chain of several makes every visitor and every crawler wait for each step.

Search engines. The X-Robots-Tag header can tell search engines not to index a page, with the same effect as a robots meta tag in the page’s code. Google supports it. Because it isn’t in the page’s code, it is easy to miss. The report also shows a canonical address or language versions given in a Link header, and the content type.

Caching and compression. Cache-Control, ETag and Last-Modified tell browsers whether they may keep a copy and how to check that it is still current. Content-Encoding shows whether the page is sent compressed.

Security. A few headers ask the browser to protect visitors: to use only the encrypted address (Strict-Transport-Security), not to guess file types (X-Content-Type-Options), to limit where scripts may load from (Content-Security-Policy), to stop other sites showing the page in a frame (X-Frame-Options), to limit what is passed on when a visitor follows a link (Referrer-Policy), and to switch off browser features the site doesn’t use, such as the camera (Permissions-Policy).

For each of them the report shows the value and checks it: a header can be present and still do little, for example a Strict-Transport-Security with a very short lifetime, or a Content-Security-Policy that allows “unsafe-inline”.

Three more headers are checked but are optional: Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy and Cross-Origin-Resource-Policy. They separate your page and its files from other sites. The opener policy suits most sites. The embedder policy is needed only for a few advanced browser features and can stop content from other sites from loading, so it isn’t right for every site.

Server software. Some servers name the software behind the site. The report shows four such headers: Server (the web server, such as nginx, Apache or LiteSpeed), the PHP version from X-Powered-By, X-Page-Speed (sent by the PageSpeed module for nginx and Apache) and X-Turbo-Charged-By (sent by LiteSpeed). “Not sent” is not a fault here: hiding these, version numbers above all, is the safer choice.

What is a good result?

There is no official score for headers, so this report doesn’t give one. The sign at the top sums up the findings below it. A tick means nothing needs attention. An exclamation mark means there are things worth a look, such as a missing security header, no compression or a chain of redirects. A cross means something is seriously wrong: the page doesn’t answer with status 200, it is served without encryption, or a header keeps it out of search results.

Which findings count as serious is Seokla’s own judgment. A “noindex” in X-Robots-Tag is treated as serious because it removes a page from search; if you set it on purpose, you can ignore it. The three cross-origin headers are optional and don’t affect the sign.

What this test can’t tell you

Headers show what the server announces, not whether it is right for your site. A strict caching rule can be correct for a shop’s basket and wrong for a blog post. The security headers are widely recommended, but their absence doesn’t mean a site has been broken into, and their presence doesn’t prove it is safe.

We check one address at one moment. Headers often differ between pages, between logged-in and anonymous visitors, and from one server location to another. Search engines don’t use security headers for ranking; they are here for your visitors’ sake.