WEB & TLS

HTTP Header Checker

View HTTP response headers and get a basic assessment of HSTS, CSP, framing, MIME sniffing and referrer policy.

39DExternal testRuns from the toolbox server

RUN TEST

HTTP Header Checker

Public targets only

HOW IT WORKS

About the HTTP Header Checker

Headers describe response handling, caching, content type and browser security policy. The checker reports the final response and highlights whether several widely used defensive headers are present.

How to use this result

  1. Run the test from this server.Use a public hostname, address, prefix or ASN in the format requested above.
  2. Compare with another observation point.Run a local command or use a second provider to identify location-specific behaviour.
  3. Correlate related evidence.Use the related tools below to compare DNS, routes, ports, TLS and application responses.
  4. Keep the time and context.Routing, DNS caches and reputation data change, so record when the result was collected.

Common interpretation issues

  • Header presence alone does not prove that a policy is correctly designed.
  • CSP can break applications when deployed without testing.
  • HSTS should only be enabled after HTTPS is reliable across the required hostnames.

NEED HELP INTERPRETING THE RESULT?

39D supports business networks, cyber security and managed IT.

For ongoing support or a larger infrastructure project, speak to the 39D team.

Visit 39D

Frequently asked questions

Is a high score a penetration test?

No. It is a focused configuration check, not a full vulnerability assessment.

Should every site use the same CSP?

No. CSP must match the scripts, styles, frames and connections genuinely required by the application.