All Tools View Categories About Contact Privacy

Live Site Header Inspector

Read pasted response headers and surface security and caching observations.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your header inspection report will appear here.
-
headers
-
findings

About Live Site Header Inspector

Response headers are the quiet control plane of every HTTP exchange: they decide whether a browser upgrades to HTTPS, blocks sniffing, constrains scripts, or caches a response for an hour. The trouble is that headers are easy to forget and even easier to misconfigure, and most teams only discover a missing HSTS or a leaky Referrer-Policy after an incident. The Live Site Header Inspector lets you paste a block of response headers and immediately see a structured report of security and caching observations, without making any live request to the target.

At the heart of the configuration are a handful of directives. Strict-Transport-Security tells browsers to enforce HTTPS for the host and its subdomains, closing downgrade attacks. Content-Security-Policy constrains the sources of scripts, styles and other resources to limit cross-site scripting. X-Content-Type-Options with the nosniff value blocks MIME sniffing that can turn benign files into executable ones. X-Frame-Options prevents the page from being embedded in a frame, defending against clickjacking. Referrer-Policy controls how much of the referring URL is sent to other origins. Permissions-Policy restricts access to powerful browser features such as camera, microphone and geolocation. Cache-Control sets how, where and for how long a response may be cached. ETag provides a validator so clients can revalidate a cached response with a 304. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. Pasting request headers instead of response headers produces a meaningless report, so copy the response block from curl -I or the Network tab. A missing colon on a line makes it unparseable, so the tool rejects the whole line with a clear message. Relying only on X-XSS-Protection gives a false sense of safety because modern browsers ignore it; the report nudges you toward CSP. Conflicting Expires and Cache-Control can confuse proxies, so the report surfaces both when present. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Features

  • Strict-Transport-Security - tells browsers to enforce HTTPS for the host and its subdomains, closing downgrade attacks.
  • Content-Security-Policy - constrains the sources of scripts, styles and other resources to limit cross-site scripting.
  • X-Content-Type-Options - with the nosniff value blocks MIME sniffing that can turn benign files into executable ones.
  • X-Frame-Options - prevents the page from being embedded in a frame, defending against clickjacking.
  • Referrer-Policy - controls how much of the referring URL is sent to other origins.
  • Permissions-Policy - restricts access to powerful browser features such as camera, microphone and geolocation.
  • Cache-Control - sets how, where and for how long a response may be cached.
  • ETag - provides a validator so clients can revalidate a cached response with a 304.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Obtain the response headers (curl -I, browser devtools, or a proxy).
  2. Paste them into the text area, one header per line as Name: value.
  3. Click Inspect headers (or Load sample to see a worked example).
  4. Read the Security observations for missing or weak headers.
  5. Read the Caching observations for Cache-Control, ETag and friends.
  6. Follow the Recommendations to close the biggest gaps.
  7. Copy, download or print the report for your change request.

Examples

Example 1 - Secure host a full set with HSTS, CSP, nosniff and a Cache-Control yields mostly green observations.

Example 2 - Missing HSTS a bare Server header triggers the Add Strict-Transport-Security recommendation.

Example 3 - Caching present Cache-Control plus ETag is reported as supporting conditional revalidation.

Example 4 - Unparseable line a line without a colon is rejected with a specific error before any report is built.

Example 5 - Privacy leak no Referrer-Policy is flagged so full URLs do not leak to third parties.

Benefits

  • Clear split between security and caching observations.
  • Detects the most common missing security headers.
  • Surfaces cache-relevant headers in one place.
  • Actionable recommendations for each gap.
  • No live connection - fully private analysis.
  • Copy, download and print exports of the report.

Frequently Asked Questions

Does this tool fetch a live URL?
No. You paste the response headers yourself; the tool only analyses the text you provide and never opens a network connection.
Where do I get the headers to paste?
Use curl -I https://yoursite, a browser developer-tools Network tab, or any proxy that shows response headers, then copy them in.
What does the security section cover?
It looks for HSTS, CSP, X-Content-Type-Options, clickjacking protection, Referrer-Policy and Permissions-Policy, and flags any that are missing.
What does the caching section cover?
It summarises Cache-Control, Expires, ETag, Last-Modified, Vary and Pragma so you can see how the response will be cached.
Why is my X-XSS-Protection noted as deprecated?
Modern browsers ignore X-XSS-Protection in favour of Content-Security-Policy, so the report flags it but recommends CSP.
Can I export the report?
Yes - the report is plain text you can copy, download or print from the action buttons.
Is anything uploaded?
No. All analysis happens locally in your browser; nothing you paste leaves the page.
Does it validate header values?
It recognises standard header names and reports their presence and value; it does not deeply validate every possible value syntax.