My Tool Studio
Webmaster & Network·5 min read

Security Headers Explained: HSTS, CSP and Caching

Before a browser draws a single pixel, the server has already said the important things about the response in its headers. Security policy, cache lifetime, redirect target and content type are all declared up front, which makes a header check the fastest read in web debugging. This guide covers the security headers that matter, the caching and SEO headers next to them, and the real values you can compare against your own site in about a minute.

HTTP headersFoundStatus200 OKServernginxTypetext/htmlCachemax-age

Why response headers are the fastest debugging read

The server states its intent.

The classic incident: you shipped a fix, the customer still sees the old page, and everyone suspects everyone else's cache. One look at the response headers usually settles it, because the server states its caching rules in cache-control, and a redirect shows up as a final URL that differs from the one you asked for.

HTTP Header Checker makes this a one-field job. Paste a URL and press Check. Our server sends a HEAD request, so no page body is downloaded, and follows up to 10 redirects. You get the status, response time and final URL, a redirect chain with each hop's status code, a security grade from A+ to F with its checklist, a caching verdict, and the full header list with a one-line meaning for common headers. Copy one value, use Copy all for a bug report, or check up to 20 URLs at once in bulk mode.

What HSTS, CSP and the other security headers enforce

Instructions, not suggestions.

strict-transport-security, known as HSTS, tells browsers to refuse plain HTTP for your domain for a set period. A value like max-age=63072000 commits visitors to HTTPS for two years and closes the window where a downgrade attack could slip in.

content-security-policy lists which sources of scripts, styles and frames the page may load, so injected script tags fail to run. x-content-type-options: nosniff stops MIME type guessing, referrer-policy limits how much URL detail leaks to other sites, x-frame-options stops other sites framing your pages, and permissions-policy switches off browser features such as the camera that a page does not need. The checklist covers all six. It tests that each header is present, not that its value is strict enough, so read the values too.

Reading cache headers: max-age, ETag and stale pages

The freshness contract.

Reading cache headers correctly saves more debugging hours than almost any other header skill. cache-control: public, max-age=31536000 means any cache may keep the response for a year, which suits fingerprinted assets like app.8f3c2.js and is a disaster for HTML. no-store forbids caching outright, no-cache means the browser must check with the server before reusing a copy, and private limits storage to the visitor's own browser.

The etag value works as a fingerprint. On revalidation the browser sends it back, and the server can answer 304 Not Modified instead of sending the body again. An age header shows how long a CDN has held its copy, and a large Age on HTML often explains why an update is not showing. When users report stale content, check these fields first. The answer is usually an HTML page that picked up an asset-style max-age.

A header check walked through

A worked example.

Check http://example.com and suppose the redirect chain reads: http://example.com 301, https://example.com 301, https://www.example.com 200. The summary shows status 200, 184 ms and the www address as the final URL. The headers include content-type: text/html; charset=utf-8, cache-control: no-cache, strict-transport-security: max-age=31536000; includeSubDomains and x-content-type-options: nosniff.

The verdict is quick. Two hops is one more than needed, since the http version could go straight to the www host. HSTS is set for a year and covers subdomains. no-cache keeps the HTML revalidated on each visit, sensible for a page that changes. The checklist flags Content-Security-Policy and Permissions-Policy as missing, and a header check is exactly how you notice a policy that vanished behind a CDN change.

Headers that affect SEO more than people expect

Crawlers read these too.

x-robots-tag is the quiet one. A noindex sent in the header blocks indexing with nothing visible in the page source, and it can stay live on a production site for months after a staging config slips through.

Redirect codes matter as much as destinations. A 301 signals a permanent move, while a 302 hints the move is temporary, and the redirect chain makes a stray 302 easy to spot. A canonical can also arrive as a link header rather than an HTML tag, which is easy to miss in audits. On large sites, cache lifetimes affect how efficiently crawlers spend their time.

Header-reading mistakes that waste an afternoon

Watch for these when you read header results:

  • Testing only the https version. The http URL may serve a long redirect chain, or real content with no redirect at all. Check both and read each hop.
  • Blaming the origin server for a header the CDN rewrote. The server header often tells you which layer answered.
  • Missing a HEAD rejection. A few servers answer HEAD with 405, and the tool tells you when that happens, because the headers you see then belong to the error, not the page.
  • Checking a page behind a login. The request carries no cookies, so you see what an anonymous visitor gets, usually a redirect to the login page.
  • Reading header names as case-sensitive. Content-Type and content-type are the same field, which is why the list shows them in lower case.

Header checks that pay off every week

Make a header check part of every deploy that touches caching, redirects or the CDN config. Half a minute confirms the intended values reached production, and it is the only reliable way to catch a security header that a proxy layer stripped.

Keep a known-good copy of your production headers in the repo or wiki. When something regresses, comparing against that copy finds the changed line far faster than trying to remember what max-age used to be.

HTTP Header Checker among its neighbours

Related checks, different depths.

When the only question is whether a URL returns 200, 301 or 500, HTTP Status Code Checker gives the leaner answer, and Redirect Checker focuses on the hops alone. To decode an unfamiliar code, the HTTP Status Codes List explains each one.

Headers also sit in front of deeper layers. If strict-transport-security is present but visitors still see certificate warnings, the problem is below the headers, and SSL Certificate Checker reads what the TLS handshake actually presents.

Try it now

Open HTTP Header Checker

The tool is one click away. No sign up, no upload, no payment.

Open HTTP Header Checker