LEARN · HSTS
HSTS (Strict-Transport-Security)
What HSTS is, which max-age to use and how to enable it without breaking your site.
WHAT IT IS
HSTS is a header telling the browser: "from now on, connect to this site only over HTTPS for X seconds". The browser never tries http:// again.
WHY IT MATTERS
It prevents an attacker on a network (public Wi-Fi, for example) from downgrading the connection to http:// on the first request of each visit.
COMMON MISTAKES
- max-age too short (at least 6 months is recommended; 1 year is typical).
- Adding includeSubDomains without checking every subdomain has HTTPS.
- Sending it only on some responses.
EXAMPLE
Strict-Transport-Security: max-age=31536000; includeSubDomains
HOW WE CHECK IT
- HDR_HSTS v1.0.0 — That HTTPS is announced with HSTS and a max-age of at least 180 days.