Skip to main content

Headers

HSTS: the security header that locks HTTPS on for good.

Published 2026-06-10 · Last updated 2026-06-10 · Vantyris editorial

HSTS (HTTP Strict-Transport-Security) is a header your site sends to every visitor, telling their browser 'always use HTTPS for this domain, never HTTP'. Without it, a visitor on a hostile Wi-Fi network can be downgraded to HTTP for the first request and quietly attacked. Enabling HSTS takes 30 minutes and closes the only remaining gap in your HTTPS setup.

What this means for your business

How to fix

Add Strict-Transport-Security: max-age=86400 for a day and confirm nothing breaks. Then increase it in stages to max-age=31536000; includeSubDomains; preload.

  1. Start small (1 day). At your web host or CDN, add the header Strict-Transport-Security: max-age=86400 to every response. 86400 is one day in seconds, so if anything breaks, the impact clears in 24 hours.
  2. Watch for a week, then go to one week. If nothing broke, raise max-age to 604800 (one week). Confirm again.
  3. Go to one year and add includeSubDomains. The final value is max-age=31536000; includeSubDomains. It protects your domain AND every subdomain, so only add includeSubDomains once you're certain every subdomain serves HTTPS.
  4. (Optional) Apply for HSTS preload. Add ; preload to the directive and submit your domain at hstspreload.org. Once it's approved, your domain ships built into every major browser's HSTS list, and visitors are protected even on their very first visit. This is hard to undo, so be sure first.

Owner: Your web host or developer. · Time: 30 minutes for the initial setup, then 2 weeks of progressive rollout to reach the final value.

Common gotchas

How to verify the fix

In Chrome DevTools, open Network, click any request to your domain and look for strict-transport-security under Response Headers. Or run a Vantyris scan, which reports the directive's max-age and flags weak values.

Cyber Essentials alignment

This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):

Vantyris is not a CE certifying body. The mapping above is informational.

Common follow-up questions

What's a 'good' max-age?

One year (31536000 seconds) is the industry standard for production sites. HSTS preload requires at least one year, plus includeSubDomains and preload.

Does HSTS work for subdomains?

Only if you include includeSubDomains in the directive. Otherwise it applies only to the exact host that served it.

What's HSTS preload?

A list of domains that browsers ship with HSTS already applied, so your domain is protected even on a visitor's first ever visit. Chromium maintains the list, and Firefox and Safari base their own preload lists on it. Submit at hstspreload.org.

References

Related explainers

Want Vantyris to check your domain for this and 196 other problems?

The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.

Written by Vantyris