Guides & reference
Understand what your headers are telling you
HTTP response headers control how browsers load a page, store its content and handle cookies. Use HeaderScan to inspect the final response, then use these guides to turn a missing header or an unexpected value into a focused change. Start with the policy that affects your page, and check the response again after deploying it.
HTTP security headers: what to check first
Understand CSP, HSTS and framing protection, then work through security header findings without breaking your website.
Read guide CachingCache-Control explained: no-cache, no-store and private
Choose a cache policy for public assets and personal pages, and understand why no-cache still allows storage.
Read guide CookiesSecure, HttpOnly and SameSite cookies explained
Learn what each cookie attribute controls and how to review session cookies without breaking login or payment flows.
Read guideHTTP response headers reference: security, cookies and caching
Look up common HTTP response headers, their purpose and the checks to make before changing a policy.
Open reference