What you are looking at
These are the headers your browser actually sent us on the request that produced this page — not a demonstration and not a sample. Anti-fraud systems, bot filters and CDNs read the same set, and they read it as a whole: it is the combination that looks ordinary or looks assembled, far more than any single line.
A few carry more weight than the rest. User-Agent claims your browser and system, and it is the easiest thing in the list to contradict. Accept-Language announces your languages, and a mismatch between it, your IP's country and your time zone is one of the cheapest signals a site can act on. Accept and Accept-Encoding vary by browser in ways a scripted client rarely reproduces exactly. Sec-Fetch-* and the Sec-CH-UA client hints are set by the browser and cannot be forged from page JavaScript, which is why they are trusted more than the User-Agent. Via, Forwarded and X-Forwarded-For appear only when something sits in the middle — a proxy that adds them is telling every server exactly that.
How the page is produced
The list is printed on the server from the incoming request, so it reflects the raw request and not something JavaScript reconstructed afterwards. The values of Cookie, Authorization, Proxy-Authorization and X-Api-Key are replaced with a placeholder: the header name is worth seeing, the value is a credential, and this page is public and gets screenshotted.
When you need it
You are testing whether a proxy or an anti-detect browser adds headers that give it away.
A scraper is being blocked and you want to compare its request with a real browser's, line for line.
You changed your User-Agent and want to check whether the client hints still contradict it.
You are debugging a CDN or a reverse proxy and need to see what actually reaches the origin.
Clean headers are necessary and not sufficient. Once JavaScript runs, a site can read your canvas, your GPU, your fonts and your time zone — signals that survive a header rewrite and do not change when your IP does. That side is visible on the fingerprint test. And nothing in this list shows whether your browser leaks your real address over WebRTC; that needs the WebRTC leak test.
Frequently asked questions
Which headers reveal that I am using a proxy?
Chiefly Via, Forwarded, X-Forwarded-For, X-Real-IP and X-Proxy-ID. A transparent proxy adds them with your real address inside; an anonymous one adds a proxy header without an address; an elite proxy adds none of them at all.
Can I change the headers my browser sends?
Some of them, with an extension or a developer-tools override — User-Agent and Accept-Language are the usual targets. Client hints such as Sec-CH-UA are set by the browser itself, which is why a changed User-Agent that contradicts them is more conspicuous than leaving it alone.
Why are the values of some headers hidden?
Cookie, Authorization, Proxy-Authorization and X-Api-Key are credentials. The name tells you the header was sent, which is the useful part; the value would let anyone who sees a screenshot of this page act as you.
Do these headers identify me personally?
Not on their own. Together with your IP, screen size and JavaScript-readable properties they can form a fingerprint distinctive enough to recognise you across sessions without a single cookie.
What are Sec-Fetch headers for?
They describe the context of the request — whether it came from navigation, an image, a script, a same-site page or a cross-site one. Servers use them to reject requests that claim to be one thing and are structured like another.
Why does my request have fewer headers than someone else’s?
Header sets differ by browser, version, platform and privacy extensions, and a proxy in the path can add or strip lines. A short set is not a problem in itself — a set that does not match the browser it claims to be is.