📨 Public URL header fetch · SSRF blocked

HTTP Response Headers

Enter an https URL. We follow a limited number of redirects and show the status code plus response headers. Private and reserved addresses are refused.

Fetch headers

🌐
Honest note: Our server requests the URL so it can read response headers. Only public hosts on ports 80 and 443 are allowed. Redirects are limited. The URL is visible to this API. Do not submit URLs that contain secrets.

See status codes and response headers

Check redirects, cache-control, content-type, security headers (HSTS, CSP, X-Frame-Options), and server banners for a public URL. This is a single fetch with a short redirect limit — not a crawler.

Frequently asked questions

Will you fetch private IPs or localhost?

No. After DNS resolution, private, loopback, link-local, CGNAT, and reserved addresses are blocked, including on redirects.

How many redirects?

Up to 5. Each hop is re-checked for public IPs.

Do you download the whole page?

We request the URL and keep response headers. Any body read is capped and discarded; the tool displays headers and status.

Which schemes are allowed?

http and https only, on ports 80 and 443.