Response header viewer

Enter an address and read what the server says before it sends the page: the status line and each header, for every redirect along the way. A short note beside each header says what it’s doing there.

Any public http:// or https:// address. Without a scheme, HTTPS is used.

Or try github.com, wikipedia.org

The part of a web page you never see

A response from a web server is put together like a parcel. The page is what’s in the box. On the outside there’s a label, made of a first line with a three-digit status code and then a list of Name: value lines called headers. The browser reads the label first and decides almost everything from it: whether to display or download, whether to keep a copy, whether to go somewhere else, which cookies to store.

You never see headers on screen, so a lot of puzzling behavior hides in them. A page that won’t update, a redirect that loops, a font blocked on another domain, a login that doesn’t stick. More often than not, it’s one header with the wrong value.

What this viewer does

Our server sends one GET request to the address you enter, the same kind a browser sends, and records the answer. If the answer is a redirect (a 3xx status with a Location header), it requests the new address and records that too, up to eight times. You get one block per response, in order, so you can see which server added which header at which step.

We look each header up in a dictionary of more than 130 names and show it with its family and a one-sentence explanation. The families are:

FamilyTypical headersQuestion they answer
CachingCache-Control, ETag, Age, X-CacheMay this be stored, for how long, and did a cache answer?
ContentContent-Type, Content-Encoding, Content-LengthWhat is in the body and how is it packed?
SecurityStrict-Transport-Security, Content-Security-PolicyWhich browser protections are switched on?
CookiesSet-CookieWhat should the browser remember?
Cross-originAccess-Control-Allow-OriginMay scripts on other sites read this?
ConnectionAlt-Svc, Date, Keep-AliveHow is the link to the server managed?
Server and CDNServer, Via, CF-RAY, X-Served-ByWhich software and which network answered?
DiagnosticsServer-Timing, X-Request-IdHow long did it take, and how to find it in the logs?

A name that isn’t in the dictionary is marked as a custom or uncommon header. Any software is free to invent its own, so you’ll see that label a lot and it’s harmless. Durations and sizes are converted where it helps, so max-age=31536000 is shown as 365 days.

The summary gives the final status, the HTTP version our server negotiated, the number of redirects, the software named by the Server header and the number of headers in the last response. Nothing gets graded here. If you want a score, the security headers grade gives one.

Reading the status line

  • 2xx: the request succeeded. 200 is the ordinary case.
  • 301 and 308: moved for good. Browsers and search engines remember the new address. 302, 303 and 307: go there for now, and keep the original as the reference.
  • 4xx: the server refuses, or can’t find what was asked for. A 403 on a page that opens fine in your browser often means the site blocks automated requests.
  • 5xx: the server itself failed. Codes from 520 to 526 come from a CDN that couldn’t reach the server behind it.

Four things people check with it

“Why do visitors still get the old version?”
Read Cache-Control and Age. A long max-age on an HTML page means browsers won’t ask again until it runs out. An X-Cache or CF-Cache-Status of HIT means the CDN served its own copy and needs a purge.
“Is compression on?”
Look for Content-Encoding: br, gzip or zstd. If the header is missing on an HTML page, the page travels at full size.
“Where does this redirect come from?”
Compare the Server header of each step. A redirect answered by the CDN was set in its dashboard. One answered by nginx or Apache is in the server configuration. One carrying X-Redirect-By names the application or plugin that issued it.
“What is this site running?”
Server, X-Powered-By and Via often name the web server, the language and the CDN. On your own site, it’s worth taking the version numbers out of those headers.

You’re looking at the headers our server received for one anonymous request. A site may answer differently to a logged-in visitor, a mobile browser, another country or another Accept-Language. Header names are shown in their usual spelling. HTTP/2 and HTTP/3 transmit them in lowercase, as the raw block does, and the case never matters.

Questions people ask

How do I see the response headers in my own browser?

Open the developer tools (F12, or Cmd+Option+I on a Mac), go to the Network tab, reload the page and click the first request. The Headers panel shows the same lines. This viewer is for when you can’t do that: on a phone, for a link you’d rather not open, or to see the answer given to a client that has no cookies.

What is the difference between request headers and response headers?

Request headers go out with the browser’s question: which page, which languages and formats it accepts, which cookies it holds. Response headers come back from the server with the answer. This page only shows response headers.

Are the X- headers standard?

The X- prefix was a convention for unofficial headers. Some became universal anyway, such as X-Frame-Options and X-Content-Type-Options. The convention was retired in 2012, so newer custom headers often have no prefix at all.

Why do I get different headers from the ones my browser shows?

Because it isn’t the same request. Servers and CDNs adapt to the client’s user agent, cookies, language and location, and a cached copy can carry headers produced hours earlier. The Vary header lists which request headers the server takes into account.

Should I hide the Server and X-Powered-By headers?

Hiding the product name changes little. Removing the version numbers is worth the two minutes, though, because automated scanners use them to pick which known flaws to try. In nginx use server_tokens off;, in Apache ServerTokens Prod, in PHP expose_php = Off.

Does a missing header mean something is wrong?

Usually not. Content-Type is the only one expected on nearly every response with a body. The others matter depending on what you want. Without Cache-Control, caching is left to each browser’s guess, and without security headers the optional protections stay off.