MYTHOSAI

Tool tutorials / PRACTICAL GUIDE

Inspect HTTP security headers with curl

Read the response headers from your own site and understand what they do—and do not—prove.

Before you start

curl and permission to test the website; no online scanning service required.

Inspect the response you actually use

Security headers can reduce specific browser risks. Their usefulness depends on correct configuration and application behaviour. A header checklist is not a complete security audit, and presence alone does not prove that a policy is effective.

For your own website, request headers with:

bash
curl -I --max-time 15 https://your-domain.example/

Replace the example domain. On Windows PowerShell, use curl.exe to explicitly invoke curl on systems where curl is a shell alias.

Watch redirects and methods

The first response might be a redirect. Add -L if you want to follow it, and distinguish each response block from the final destination. A HEAD request can behave differently from GET. If HEAD is unsupported, inspect a GET response while discarding the body:

bash
curl -sS -D - -o /dev/null --max-time 15 https://your-domain.example/

On Windows, use NUL instead of /dev/null. Do not attach session cookies or tokens to a command you will publish.

Review important fields

Look for Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options and Referrer-Policy. Also inspect cache controls on private or authenticated responses. Each serves a different purpose: script-source restrictions, HTTPS persistence, MIME interpretation and referrer disclosure are not interchangeable.

A CSP allowing every source or extensive unsafe behaviour can be weak despite its presence. HSTS should be deployed only when the covered hosts are ready for HTTPS; an unreviewed includeSubDomains or preload decision can break access.

Verify with the browser

Use developer tools to inspect the main document response and any console policy violations. Test actual navigation, forms and required scripts after a change. A report-only CSP helps observe violations but does not enforce blocking.

Common mistakes

Reading a redirect's headers as the final page's policy produces the wrong conclusion. Cloudflare or another proxy can add or modify headers, so the public response matters. Do not remove security controls simply to silence an error without identifying the blocked dependency.

Keep the outcome specific

Record URL, response status, method and the relevant policy values. Recommend a change for a concrete risk, then test the application. Do not give a site a perfect security score solely because several header names appear.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.