Skip to content

HTTP security

HSTS checker

Read the Strict-Transport-Security header a site sends and check that plain HTTP is redirected to HTTPS: the two settings that decide whether a browser ever talks to the site without encryption.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

HSTS (RFC 6797) tells a browser that, for the next max-age seconds, this host must only be reached over HTTPS. The browser then upgrades http:// links and typed addresses itself, before any request leaves, and does not let the visitor click through a certificate warning.

Browsers ignore the header on plain HTTP responses, which is why the redirect matters. A first-time visitor who types the bare name arrives over HTTP, and the redirect is what brings them to the HTTPS response that carries the header. That first request, and any after max-age runs out, can still be intercepted.

A pass on both checks means plain HTTP redirects to HTTPS and the header asks browsers to remember that for at least 180 days. A short max-age is low severity: the protection works, but lapses for anyone who visits less often than it lasts.

How to fix common issues

HSTS is not enabled

Add Strict-Transport-Security: max-age=31536000; includeSubDomains to HTTPS responses once every subdomain serves HTTPS. Start with a short max-age if you are unsure, then raise it.

More in the HTTP Strict Transport Security check reference

HSTS max-age is short

Raise max-age to at least one year (31536000 seconds).

More in the HTTP Strict Transport Security check reference

HTTP is not redirected to HTTPS

Redirect every HTTP request to the same path over HTTPS with a 301 or 308. Most hosts and CDNs have an "Always use HTTPS" setting.

More in the HTTP to HTTPS redirect check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 names HSTS. Keeping web traffic on HTTPS is technical evidence for ISO/IEC 27001:2022 Annex A 8.24 (use of cryptography) and 5.14 (information transfer).

What the organisation establishes itself is the rule behind the header: that its public sites are HTTPS only, who decides when includeSubDomains or preloading is safe, and how certificates on every covered name are kept valid so the rule can hold.

Scope and limitations

Related guides

Questions

What max-age should HSTS use?
One year (31536000 seconds) is the usual choice, and this check reports anything under 180 days as short. Start lower while you confirm every name serves HTTPS, then raise it.
Should I add includeSubDomains?
Only once every subdomain, including internal and forgotten ones, serves HTTPS with a valid certificate. Browsers will refuse plain HTTP on all of them for the length of max-age.
Does HSTS protect the very first visit?
No. A browser learns the rule from the first HTTPS response it sees, so the first request can still go over HTTP. Preloading the domain into browsers closes that gap, but it is hard to undo.

Related security tools