Headers Check
Inspect HTTP response and security headers for a public website.
What are HTTP security headers?
HTTP security headers are response headers that instruct browsers how to handle certain security-sensitive behaviors. Common examples include Content-Security-Policy, Strict-Transport-Security, X-Frame-Options and Referrer-Policy.
Security headers are only one layer of web security. Their presence can reduce exposure to certain attack classes, but they do not replace secure application code, correct server configuration or regular vulnerability testing.
How to check website security headers
- Enter the public website or hostname you want to inspect.
- Run the header check.
- Review the detected response headers and the status of common security controls.
Understanding security header results
A present header means the website returned that control in the HTTP response inspected by WhatAnIP. The exact value matters because a poorly configured policy can be ineffective even when the header itself exists.
A missing header should not automatically be treated as a vulnerability. Some controls are unnecessary in certain architectures, while others may be enforced through different mechanisms. Results should be interpreted together with the application design.
Common uses for security header checks
- Review website hardening after deployment.
- Check whether HSTS and CSP headers are being returned.
- Investigate framing or referrer-policy configuration.
- Compare production and staging server responses.
- Perform a quick configuration review before deeper security testing.