Network Diagnostic Tools

HTTP Header Check

Inspect response headers, redirects and security

About this tool

HTTP response headers reveal how a web server behaves: the status code it returns, where it redirects, what software it runs and which security hardening headers it sends. Missing headers like HSTS, Content-Security-Policy or X-Frame-Options leave sites exposed. IPeek follows the full redirect chain and grades the response against the key security headers.

Frequently asked questions

Which security headers should every site send?

At minimum: Strict-Transport-Security (HSTS), Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.

What does the redirect chain show?

Every hop a request takes — for example HTTP to HTTPS, or apex to www — so you can spot redirect loops or extra hops.

Why is HSTS important?

HTTP Strict Transport Security forces browsers to use HTTPS, preventing downgrade attacks.

Related tools

Deutsch | English | Español | Français | Italiano | Português | Русский | Українська | 日本語 | 简体中文 | 한국어