HTTP security
HSTS checker
Read the Strict-Transport-Security header a site sends and check that plain HTTP is redirected to HTTPS: the two settings that decide whether a browser ever talks to the site without encryption.
What this checks
- The
Strict-Transport-Securityheader on any HTTPS response for the home page, including a redirect before the final page, for the domain and itswww.name, or the subdomain entered. - Its
max-age. A missing header,max-age=0or a value that does not parse counts as no HSTS; under 15,552,000 seconds (180 days) counts as short. - Whether
includeSubDomainsandpreloadare present. Both are shown; neither is judged. - Whether
http://on each name answers with a redirect to HTTPS, following up to three redirects. If port 80 does not answer, there is nothing to redirect and that check does not apply.
What the result means
HSTS (RFC 6797) tells a browser that, for the next max-age seconds, this host must only be reached over HTTPS. The browser then upgrades http:// links and typed addresses itself, before any request leaves, and does not let the visitor click through a certificate warning.
Browsers ignore the header on plain HTTP responses, which is why the redirect matters. A first-time visitor who types the bare name arrives over HTTP, and the redirect is what brings them to the HTTPS response that carries the header. That first request, and any after max-age runs out, can still be intercepted.
A pass on both checks means plain HTTP redirects to HTTPS and the header asks browsers to remember that for at least 180 days. A short max-age is low severity: the protection works, but lapses for anyone who visits less often than it lasts.
How to fix common issues
HSTS is not enabled
Add Strict-Transport-Security: max-age=31536000; includeSubDomains to HTTPS responses once every subdomain serves HTTPS. Start with a short max-age if you are unsure, then raise it.
HSTS max-age is short
Raise max-age to at least one year (31536000 seconds).
HTTP is not redirected to HTTPS
Redirect every HTTP request to the same path over HTTPS with a 301 or 308. Most hosts and CDNs have an "Always use HTTPS" setting.
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 names HSTS. Keeping web traffic on HTTPS is technical evidence for ISO/IEC 27001:2022 Annex A 8.24 (use of cryptography) and 5.14 (information transfer).
What the organisation establishes itself is the rule behind the header: that its public sites are HTTPS only, who decides when includeSubDomains or preloading is safe, and how certificates on every covered name are kept valid so the rule can hold.
Scope and limitations
- Only the domain and its
www.name are visited. Other subdomains are not, so the check cannot tell whetherincludeSubDomainswould cut off one that still serves plain HTTP. - It does not look up the browsers' preload list. The
preloaddirective asks to be included; whether the domain is on the list is shown at hstspreload.org. - The redirect check looks at the home page only. It does not test that every path redirects or that the redirect keeps the path.
Related guides
Questions
- What max-age should HSTS use?
- One year (31536000 seconds) is the usual choice, and this check reports anything under 180 days as short. Start lower while you confirm every name serves HTTPS, then raise it.
- Should I add includeSubDomains?
- Only once every subdomain, including internal and forgotten ones, serves HTTPS with a valid certificate. Browsers will refuse plain HTTP on all of them for the length of max-age.
- Does HSTS protect the very first visit?
- No. A browser learns the rule from the first HTTPS response it sees, so the first request can still go over HTTP. Preloading the domain into browsers closes that gap, but it is hard to undo.
Related security tools
- SSL/TLS checker - Check a site's HTTPS, certificate, expiry, TLS versions and weak cipher suites.
- Certificate expiry checker - See when a site's TLS certificate expires and how many days are left.
- HTTP security headers checker - Check a site's HSTS, CSP, framing, content-type, referrer and permissions headers.

