Headers
HSTS: the security header that locks HTTPS on for good.
Published 2026-06-10 · Last updated 2026-06-10 · Vantyris editorial
HSTS (HTTP Strict-Transport-Security) is a header your site sends to every visitor, telling their browser 'always use HTTPS for this domain, never HTTP'. Without it, a visitor on a hostile Wi-Fi network can be downgraded to HTTP for the first request and quietly attacked. Enabling HSTS takes 30 minutes and closes the only remaining gap in your HTTPS setup.
What this means for your business
- Without HSTS, every visit to your site starts with a brief HTTP request (when the visitor types your domain or follows an old link) that then redirects to HTTPS. That brief window is enough for an attacker on the same network to intercept it and serve a fake HTTPS page.
- HSTS removes the window. After one visit with HSTS in place, the browser caches the directive and refuses to use HTTP for your domain for as long as the
max-agesays. - HSTS is sticky. If you publish a year-long policy and your HTTPS then breaks, visitors who've already seen your site can't reach it at all until the cache expires. That's why you start with a short
max-age.
How to fix
Add Strict-Transport-Security: max-age=86400 for a day and confirm nothing breaks. Then increase it in stages to max-age=31536000; includeSubDomains; preload.
- Start small (1 day). At your web host or CDN, add the header
Strict-Transport-Security: max-age=86400to every response. 86400 is one day in seconds, so if anything breaks, the impact clears in 24 hours. - Watch for a week, then go to one week. If nothing broke, raise
max-ageto 604800 (one week). Confirm again. - Go to one year and add
includeSubDomains. The final value ismax-age=31536000; includeSubDomains. It protects your domain AND every subdomain, so only addincludeSubDomainsonce you're certain every subdomain serves HTTPS. - (Optional) Apply for HSTS preload. Add
; preloadto the directive and submit your domain at hstspreload.org. Once it's approved, your domain ships built into every major browser's HSTS list, and visitors are protected even on their very first visit. This is hard to undo, so be sure first.
Owner: Your web host or developer. · Time: 30 minutes for the initial setup, then 2 weeks of progressive rollout to reach the final value.
Common gotchas
- Do NOT jump straight to a one-year
max-age. If your HTTPS setup has a bug, you've just told every visitor's browser to refuse HTTP fallback for a year. Start small. includeSubDomainsis opt-in for a reason. If a subdomain (e.g., a legacy mail server or staging site) serves HTTP only, it becomes unreachable from any browser that's seen your main domain. Audit subdomains first.- Removing HSTS once it's been served is hard, because the browser remembers. You can publish
max-age=0to clear it, but only visitors who hit your site after that change will see it. Be careful before opting in.
How to verify the fix
In Chrome DevTools, open Network, click any request to your domain and look for strict-transport-security under Response Headers. Or run a Vantyris scan, which reports the directive's max-age and flags weak values.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
What's a 'good' max-age?
One year (31536000 seconds) is the industry standard for production sites. HSTS preload requires at least one year, plus includeSubDomains and preload.
Does HSTS work for subdomains?
Only if you include includeSubDomains in the directive. Otherwise it applies only to the exact host that served it.
What's HSTS preload?
A list of domains that browsers ship with HSTS already applied, so your domain is protected even on a visitor's first ever visit. Chromium maintains the list, and Firefox and Safari base their own preload lists on it. Submit at hstspreload.org.
References
Related explainers
- HTTPS for small business: how to enable it in 15 minutes.
- Content Security Policy: the header that stops most XSS attacks dead.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris