Contact

What is HSTS (HTTP Strict Transport Security)?

Definition

HSTS (HTTP Strict Transport Security) is a mechanism by which a site uses the Strict-Transport-Security response header to tell browsers to connect to it only over HTTPS for a set period. During that time the browser rewrites http:// addresses to https:// before sending anything and refuses to let users click through certificate errors, closing the gap that attacks on the first plain-HTTP request rely on.

Also known as: HTTP Strict Transport Security, Strict-Transport-Security, HSTS header, HSTS preload

HSTS header diagram: once received, the browser upgrades typed http addresses to https internally before any request is sent

The gap a redirect leaves open

Most sites send HTTP requests to HTTPS with a 301 redirect. But when someone types just the domain name or follows an old http:// link, that first request travels unencrypted. An attacker on the same network can intercept it and keep the victim on a plain or spoofed version instead of passing the redirect through, a technique known as SSL stripping. HSTS lets the browser skip that vulnerable first hop entirely.

Once a browser has received the header over HTTPS, it converts every http:// request for that host to https:// internally, before anything leaves the machine, for as long as the policy lasts. Chrome DevTools shows this as a "307 Internal Redirect"; the server never sends such a response. HSTS also removes the "proceed anyway" option on certificate errors.

Reading the header

Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
  • max-age: how long, in seconds, the browser should remember the policy. It is refreshed with every response, and max-age=0 clears it.
  • includeSubDomains: extends the policy to every subdomain.
  • preload: signals consent to inclusion in the browser-shipped HSTS list. On its own it does nothing; you still have to submit the domain.

The header only counts when it arrives over HTTPS; browsers are required to ignore it on plain HTTP responses. HSTS therefore complements the HTTP-to-HTTPS redirect rather than replacing it, and it is one of the core security headers worth setting on any HTTPS site.

Solving the first visit with preloading

A browser can only learn the policy after reaching the site over HTTPS at least once. The preload list closes that gap: maintained for Chrome and also used by other major browsers, it ships inside the browser itself. The requirements are published at hstspreload.org: a valid certificate, a redirect from HTTP to HTTPS on the same host, every subdomain served over HTTPS, and a header with max-age of at least one year (31536000 seconds) plus both includeSubDomains and preload.

Rolling it out without locking yourself out

The real danger is turning HSTS on with the wrong scope. Add includeSubDomains and any HTTP-only subdomain, such as an intranet tool, a printer interface or a legacy mail admin page, becomes unreachable in browsers immediately. Preloading extends that to internal subdomains that are not publicly reachable at all. Removal from the list is possible, but it takes months to reach users through browser updates, and other browsers update on their own schedules.

  1. Inventory every subdomain and confirm each one serves HTTPS correctly.
  2. Start with a tiny value such as max-age=300, then step up to a week and a month as long as nothing breaks.
  3. Add includeSubDomains and repeat the gradual increase.
  4. Only after months of clean operation, move to a year or more, add preload and submit.

The SEO Checker reports whether the HSTS header is present as part of its HTTPS checks.

Related terms

← Back to the glossary