Back to toolbox

HTTP headers

Fetches the URL (following redirects manually so every hop is captured), then evaluates security headers, cookie flags, and version leakage.

How this works

There is no third-party service behind this. deepdig's Go backend makes the request itself, from our server, and reports exactly what came back.

  • One real HTTP request per hop. Redirects are followed manually rather than by the HTTP client, up to 10 hops, so every intermediate status, Location and timing is captured instead of only the final response.
  • A plain GET, identifying itself as deepdig-headers/1.0. No cookies are carried between runs and nothing is submitted to the site — sites that vary by user agent or geography may answer us differently than they answer you.
  • The checks read that one response. Security headers, cookie flags, the redirect chain and server-version leakage are each evaluated in parallel against the captured exchange, then graded and explained.
  • Results stream as they finish. Each check emits findings independently, which is why the page fills in rather than appearing all at once.

The raw response is included with the findings — expand "Show raw response" on any card to see the unedited bytes.