HTTP headers
Check security headers, cookies and caching.
About this scan
Checks the final response after up to five redirects: security, cookies, caching and server information. Does not run JavaScript or send cookies.
Anyone with the result link can view the report. Reports expire after seven days. Query values and sensitive headers are redacted.
A snapshot, not a security guarantee.
From scan to solution
Understand what your headers are telling you
HTTP response headers control how browsers load a page, store its content and handle cookies. Use HeaderScan to inspect the final response, then use these guides to turn a missing header or an unexpected value into a focused change. Start with the policy that affects your page, and check the response again after deploying it.
HTTP security headers: what to check first
Understand CSP, HSTS and framing protection, then work through security header findings without breaking your website.
Read guide CachingCache-Control explained: no-cache, no-store and private
Choose a cache policy for public assets and personal pages, and understand why no-cache still allows storage.
Read guide CookiesSecure, HttpOnly and SameSite cookies explained
Learn what each cookie attribute controls and how to review session cookies without breaking login or payment flows.
Read guideA few useful answers
Frequently asked questions
Which HTTP response does HeaderScan inspect?
HeaderScan follows up to five redirects and analyzes the final response. The report covers security headers, cookies, caching and server information on that response. If the URL ends on a login screen or CDN challenge, the findings describe that page.
Does a missing security header mean my site is unsafe?
A missing header is a reason to review the intended browser policy. It is not proof of an exploitable vulnerability. Check whether the policy applies to your page and test changes against real user journeys. A high score is not a security guarantee.
HTTP security headers: what to check firstWhy are my login cookies missing from the report?
The scan does not sign in, send cookies or run JavaScript. It only sees cookies set in the final response headers. Cookies created after authentication or by a script need a separate check in your own browser session.
Secure, HttpOnly and SameSite cookies explainedWhat is the difference between no-cache and no-store?
no-cache permits storage but requires validation before reuse. no-store tells caches not to store the response. Choose the policy according to the content: a public asset and a sensitive account page have different caching requirements.
Cache-Control explained: no-cache, no-store and privateWhy do the reported headers differ from my server configuration?
The scan sees the public response after any redirects. A CDN, proxy, route-specific setting or error handler may add or replace headers. Compare the final URL with the page you intended to test, then check each layer that supplies that response.