HTTP headers are metadata sent between browser and server with every request and response. They control caching, content types, security policies and much more. Security headers like HSTS, CSP and X-Frame-Options protect against common attacks such as XSS and clickjacking. This tool shows all response headers and checks whether important security headers are present.