HTTP headers

HTTP headers are key-value pairs sent with every request and response that tell browsers and servers how to handle content, caching, security and more.
Website
Created on
29.09.2026

Summarize this

What are HTTP headers?

HTTP headers are small pieces of metadata sent along with every HTTP request and response. Each header is a name and a value, for example Content-Type: text/html. They travel before the actual content and tell the receiver how to interpret it, whether to store it, who is allowed to read it and how to secure it.

Visitors never see headers, but they shape the speed, security and search visibility of every page.

‍

How HTTP headers work

When a browser requests a page, it sends request headers. The server answers with response headers followed by the body.

GET /pricing HTTP/1.1
Host: www.example.com
Accept-Language: en

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Cache-Control: public, max-age=3600
Strict-Transport-Security: max-age=31536000

You can inspect headers in the Network tab of your browser developer tools or with a command such as curl -I.

‍

Main types of HTTP headers

  • Request headers: sent by the browser, such as User-Agent, Accept-Language and Cookie.
  • Response headers: sent by the server, such as Content-Type, Set-Cookie and Location.
  • Caching headers: Cache-Control, ETag and Expires control how long content is stored.
  • Security headers: protect visitors against common attacks.

‍

Key headers for security and SEO

HeaderPurposeWhy it matters
Strict-Transport-SecurityForces HTTPS connectionsPrevents downgrade attacks
Content-Security-PolicyRestricts allowed content sourcesReduces script injection risk
Cache-ControlDefines caching rulesImproves load speed
X-Robots-TagGives indexing directivesControls indexing of non-HTML files
LocationSets the redirect targetUsed by 301 and 302 redirects

‍

Best practices and common mistakes

  • Serve every page over HTTPS and add Strict-Transport-Security once you are sure it works.
  • Set long cache lifetimes for static assets and short ones for HTML.
  • Return the right status code and Content-Type, since wrong values can prevent indexing or break rendering.
  • Avoid leaking server details in headers such as Server or X-Powered-By.
  • Test changes on a staging environment: a strict security header can block your own scripts.

‍

HTTP headers at BeBranded

Headers sit at the boundary between performance, security and SEO. Through our website services, we configure caching, redirects and security headers at the hosting or CDN level, and we verify them with each launch so that pages are fast, safe and correctly indexed.

FAQ

HTTP headers are name-value pairs sent with every request and response. They describe the content and tell browsers and servers how to handle it.
Open your browser developer tools, go to the Network tab and select a request. You can also run curl -I followed by the URL in a terminal.
Request headers are sent by the browser to describe what it wants, while response headers are sent by the server to describe what it returns.
Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options and Referrer-Policy are the most common baseline security headers.
Yes. Status codes, redirects, caching and X-Robots-Tag directives all influence how search engines crawl and index your pages.
Add them in your web server configuration, at your CDN such as Cloudflare, or in your hosting settings, depending on where your site is served.

Ready to boost your conversions?

Our team is here to understand your needs & work with you to create your next projects.
Get news, infos and resources.
Actionable tips delivered straight to your inbox.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.