HTTP headers
What are HTTP headers?
HTTP headers are small pieces of metadata sent along with every HTTP request and response. Each header is a name and a value, for example Content-Type: text/html. They travel before the actual content and tell the receiver how to interpret it, whether to store it, who is allowed to read it and how to secure it.
Visitors never see headers, but they shape the speed, security and search visibility of every page.
How HTTP headers work
When a browser requests a page, it sends request headers. The server answers with response headers followed by the body.
GET /pricing HTTP/1.1
Host: www.example.com
Accept-Language: en
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Cache-Control: public, max-age=3600
Strict-Transport-Security: max-age=31536000You can inspect headers in the Network tab of your browser developer tools or with a command such as curl -I.
Main types of HTTP headers
- Request headers: sent by the browser, such as
User-Agent,Accept-LanguageandCookie. - Response headers: sent by the server, such as
Content-Type,Set-CookieandLocation. - Caching headers:
Cache-Control,ETagandExpirescontrol how long content is stored. - Security headers: protect visitors against common attacks.
Key headers for security and SEO
| Header | Purpose | Why it matters |
|---|---|---|
| Strict-Transport-Security | Forces HTTPS connections | Prevents downgrade attacks |
| Content-Security-Policy | Restricts allowed content sources | Reduces script injection risk |
| Cache-Control | Defines caching rules | Improves load speed |
| X-Robots-Tag | Gives indexing directives | Controls indexing of non-HTML files |
| Location | Sets the redirect target | Used by 301 and 302 redirects |
Best practices and common mistakes
- Serve every page over HTTPS and add
Strict-Transport-Securityonce you are sure it works. - Set long cache lifetimes for static assets and short ones for HTML.
- Return the right status code and
Content-Type, since wrong values can prevent indexing or break rendering. - Avoid leaking server details in headers such as
ServerorX-Powered-By. - Test changes on a staging environment: a strict security header can block your own scripts.
HTTP headers at BeBranded
Headers sit at the boundary between performance, security and SEO. Through our website services, we configure caching, redirects and security headers at the hosting or CDN level, and we verify them with each launch so that pages are fast, safe and correctly indexed.