Skip to main content
ssl

HTTP Headers

HTTP Headers helps you view http/https response headers, for certificate inspection, HTTPS validation, and TLS troubleshooting.

Enter the full URL including https://

HTTP CheckA browser window upgrades to HTTPS with a secure padlock.https://

Advertisement · Anuncio

Advertisement · Anuncio

Technical Analysis & Guide

What It Does

HTTP Headers Check retrieves and displays all HTTP response headers from a web server, showing configuration details, server information, and caching policies.

Illustration of ssl concept

Why It Matters

  • →Debugging: Understand how the server responds to requests
  • →Performance: Check caching headers to optimize load times
  • →Security: Review security-related headers
  • →Troubleshooting: Diagnose redirect issues and response codes

How to Read Results

  • Status Code: 200 (OK), 301 (Redirect), 404 (Not Found), etc.
  • Server: Web server software (Apache, nginx, etc.)
  • Cache-Control: How browsers should cache the content
  • Content-Type: Type of content being returned (HTML, JSON, etc.)

Technical Background

HTTP is a request-response protocol whose meaning is defined once in RFC 9110 (HTTP Semantics) and then carried over three wire formats: HTTP/1.1 (RFC 9112), HTTP/2 (RFC 9113) and HTTP/3 over QUIC (RFC 9114). Whatever the version, every response starts with a three-digit status code and a set of header fields. The first digit gives the class: 1xx informational, 2xx success, 3xx redirection, 4xx client error and 5xx server error. Reading the exact code is the fastest way to tell whether a problem lies with the request, the application or the infrastructure in front of it.

Redirects deserve special attention. 301 Moved Permanently and 308 Permanent Redirect tell clients and search engines to replace the old URL; 302 Found and 307 Temporary Redirect say the original URL remains canonical. 307 and 308 additionally guarantee that the method and body are preserved, so a POST stays a POST. The target is given in the Location header, which may be relative. Each extra hop in a chain such as http://example.com -> https://example.com -> https://www.example.com -> /en/ costs a full round trip, may need a new TLS handshake and dilutes crawl budget, so the goal is a single 301 or 308 from any variant straight to the final URL. Loops, where two rules keep bouncing a request back and forth, typically appear when a CDN talks plain HTTP to an origin that insists on HTTPS.

Error classes point to different layers. 404 Not Found and 410 Gone come from the application, and a page that displays 'not found' while returning 200 is a soft 404 that search engines treat as low-quality content. 401 and 403 relate to authentication and authorization, though a 403 delivered only to automated clients usually comes from a WAF rule. 502 Bad Gateway and 504 Gateway Timeout are produced by a proxy or load balancer that could not get a valid or timely answer from the upstream server, while 503 Service Unavailable often signals maintenance or overload, ideally with a Retry-After header.

Caching headers, defined in RFC 9111, decide how long browsers and CDNs may reuse a response. 'Cache-Control: public, max-age=31536000, immutable' suits fingerprinted static files, whereas personalised HTML should use 'private' or 'no-store'. The Server header reveals software and sometimes versions, which is useful for debugging but needlessly informative to attackers.

This tool makes one request to the URL you enter, adding https:// if no scheme is given, and deliberately does not follow redirects, so you see exactly what the first server answers. It reports the status code and text, the time until the response arrived, the Server, Content-Type and Cache-Control headers, four key security headers and, for 3xx responses, the Location target. 2xx is a pass, 3xx a warning that shows where the chain continues, and 4xx or 5xx a failure. On HTTPS, missing HSTS, X-Frame-Options or X-Content-Type-Options also produce warnings. Private and reserved targets are refused to prevent request forgery.

Common Errors and How to Fix Them

ProblemThe homepage passes through three or four redirects (http -> https -> www -> /en/) before content loads.
FixCollapse the rules so every variant answers with one 301 or 308 straight to the final URL. Enter each Location value shown here as a new check to map the chain hop by hop.
ProblemA permanent domain or URL change is served with 302, and search results keep showing the old address.
FixUse 301 or 308 for permanent moves. A 302 tells crawlers the original URL is still canonical, which slows the transfer of ranking signals to the new address.
ProblemThe browser shows 'too many redirects' after enabling HTTPS behind a CDN or load balancer.
FixThe proxy talks HTTP to the origin, and the origin redirects every request to HTTPS. Switch the proxy to full TLS towards the origin, or make the origin trust the X-Forwarded-Proto header before redirecting.
ProblemMissing pages display a friendly 'not found' message but return HTTP 200.
FixReturn a real 404, or 410 for permanently removed content, while keeping the friendly page body. Soft 404s waste crawl budget and can be indexed as thin content.
ProblemThis check gets 403 Forbidden while the page opens normally in a browser.
FixA WAF or bot-management rule is blocking non-browser clients. Review the rule's logs, and if uptime monitors or partners must reach the URL, add an allowlist rather than disabling protection.
ProblemStatic assets are served with 'Cache-Control: no-cache' or no caching header, so every visit re-downloads them.
FixFingerprint asset filenames (app.3f9a1c.js) and serve them with 'Cache-Control: public, max-age=31536000, immutable'. Keep HTML short-lived or revalidated so deployments appear immediately.

Frequently Asked Questions

What is the difference between 301, 302, 307 and 308?

301 and 308 are permanent; 302 and 307 are temporary. The newer codes, 307 and 308, forbid clients from changing the request method, so a POST is resent as a POST, while with 301 and 302 browsers historically switched to GET. For moving web pages, 301 or 308 both work; for API endpoints that receive POST data, prefer 308 or 307.

Why does the result show a redirect instead of my final page?

This tool intentionally does not follow redirects, so you can see each hop as the server sends it. The Location field shows where the request would go next. Paste that URL into a new check to continue along the chain; if it takes more than one step to reach a 200, consider simplifying your redirect rules.

What does the load time measure?

It is the time from our server starting the request until the response status and headers arrive. That includes DNS resolution, the TCP connection, the TLS handshake for HTTPS and the server's processing time, but not downloading the full body or rendering. It is close to time to first byte, measured from our infrastructure rather than your location.

What do 502, 503 and 504 errors mean?

All three are usually generated by something in front of the application. 502 Bad Gateway means a proxy received an invalid answer, often because the backend crashed or closed the connection. 503 Service Unavailable signals overload or maintenance. 504 Gateway Timeout means the backend was too slow. Check the application and upstream logs at the time of the error.

Should I hide the Server header?

Removing version numbers is a reasonable hardening step, for example 'server_tokens off;' in nginx, because it stops automated scanners from matching your exact build against known vulnerabilities. It is not a substitute for patching. Some CDNs always insert their own Server value, which is harmless and helps confirm that traffic is flowing through them.

Academic Documentation

Protocol context and primary references

REST API Documentation

v1.0
GET /api/tools/http-check
					curl -X POST https://epcybertools.com/api/tools/http-check \
  -H "Content-Type: application/json" \
  -d '{"url":"https://google.com"}'
				
					{
  "success": true,
  "results": [
    { "test": "Sample Check", "status": "pass", "message": "All clear" }
  ]
}
				
Rate Limit: 100 requests / 15 minutes
100-Day Max Lifespan
155d 5h 21m 6s
PQC Migration Target
1178d 5h 21m 6s