Skip to content

HTTP security configuration

What is HSTS?

Whether HTTPS responses carry a Strict-Transport-Security header, and whether its max-age is long enough to protect occasional visitors.

Part of the External Security Check. Free during the preview.

What it checks

Whether HTTPS responses carry a Strict-Transport-Security header, and whether its max-age is long enough to protect occasional visitors.

A pass means: HSTS tells browsers to use HTTPS only.

Possible findings

HSTS is not enabled

Severity: MediumConfidence: ConfirmedKind: Recommended hardening

What we found

HTTPS responses do not include a Strict-Transport-Security header.

Why it matters

HSTS tells browsers to only ever use HTTPS for your site. Without it, the first request a visitor makes can be downgraded to HTTP by an attacker on the same network.

How to fix it

Add Strict-Transport-Security: max-age=31536000; includeSubDomains to HTTPS responses once every subdomain serves HTTPS. Start with a short max-age if you are unsure, then raise it.

HSTS max-age is short

Severity: LowConfidence: ConfirmedKind: Recommended hardening

What we found

The Strict-Transport-Security max-age is under six months.

Why it matters

A short max-age means browsers forget the HTTPS-only rule quickly, so the protection lapses for occasional visitors.

How to fix it

Raise max-age to at least one year (31536000 seconds).

References