Skip to content

HTTP header checker

Enter a URL and see the response headers of every hop, including redirects.

Try: github.com, http://www.wikipedia.org, apple.com/de

See every response header of every hop

A browser only shows you the page at the end of a redirect chain. Everything that happens on the way there is hidden in the HTTP response headers. The HTTP header checker follows the complete redirect chain and lists all response headers of every hop, from the first 301 to the final 200 or error page.

That is useful when a redirect behaves differently than expected: you can see which server or CDN answered, where the Location header points, whether a hop is cached and whether security headers like HSTS are set on the right response.

The most important headers for SEO and security

HeaderWhat it doesWhat to look for
LocationThe target of a redirect. Only relevant together with a 3xx status code.It should point directly to the final URL, including the right protocol and host, not to another redirect.
Cache-ControlControls how long browsers and proxies may cache the response.Browsers cache 301 and 308 redirects aggressively. A long max-age on a redirect you may want to change later makes corrections harder.
Strict-Transport-SecurityHSTS tells the browser to use only HTTPS for this host in the future.Set it on HTTPS responses, e.g. max-age=31536000. Browsers ignore it on plain HTTP responses.
Content-TypeThe media type and character set of the response body.HTML pages should send text/html; charset=utf-8. A wrong type can break rendering or indexing.
Set-CookieSets cookies in the browser.Check Secure, HttpOnly and SameSite. Cookies set on a redirect hop for the wrong host will be missing after the redirect.
X-Robots-TagRobots directives such as noindex or nofollow as an HTTP header.An accidental noindex on the final URL removes the page from Google's index, even if the HTML contains no robots meta tag.
Link with rel="canonical"Canonical URL as an HTTP header, common for PDFs and other non-HTML files.It should name the final, preferred URL and not contradict the redirect or the canonical tag in the HTML.
Server, Via, X-CacheReveal which software, proxy or CDN generated the response.Helps you find out whether a redirect comes from your web server, your CMS or a CDN such as Cloudflare.

How to use the header checker

Enter a domain or URL and choose a user agent. If you leave out the scheme, http:// is added, so you can also check the HTTP to HTTPS step. The result shows each hop with its status code and the full list of response headers underneath.

Some typical findings:

  • HSTS missing on the final URL: add Strict-Transport-Security to your HTTPS responses. See the guide on redirecting HTTP to HTTPS.
  • A different Server header on the first hop: the redirect happens at a CDN or load balancer, not in your web server configuration. That is where you have to change it.
  • A Location header pointing to another redirect: update the rule so it points straight to the final URL.
  • X-Robots-Tag: noindex on a page that should rank: check your server configuration or SEO plugin.

If you only need the status codes and the final URL, the redirect checker gives you a more compact view. For the meaning of each code, see the HTTP status code reference.

Frequently asked questions

Why are the headers of the intermediate hops important?

Each hop is a separate HTTP response, possibly from a different server. A Set-Cookie, a caching rule or a security header on a redirect hop only applies to that response. By looking at every hop you can see where a redirect is generated and whether headers are set on the response where they actually take effect.

Do search engines read the X-Robots-Tag and Link headers?

Yes. Google supports X-Robots-Tag with the same directives as the robots meta tag, and it accepts rel="canonical" in the Link HTTP header. Both are especially useful for non-HTML files such as PDFs. Details are in the Google Search Central documentation.

Should the HSTS header also be sent on the HTTP to HTTPS redirect?

It does no harm, but it has no effect: browsers ignore Strict-Transport-Security on responses delivered over plain HTTP. What matters is that it is present on HTTPS responses, including the final URL. Once a browser has seen it, it goes straight to HTTPS on the next visit and skips the redirect.

More free tools

  • Bulk checker

    Check up to 20 URLs at once, e.g. your redirect map after a domain migration. Export as CSV.

  • .htaccess redirect generator

    Generate Apache .htaccess rules for single pages, HTTPS and www redirects.

  • nginx redirect generator

    Generate nginx server blocks and return rules for your redirects.

  • HTTP status codes

    All HTTP status codes explained, with notes on how Google treats them.

  • JSON API

    Check redirects from your scripts and CI pipelines with a simple JSON API.