What is Strict-Transport-Security?
HTTP Strict Transport Security (HSTS) tells browsers to use HTTPS for future visits to your host (and optionally subdomains). It is sent on HTTPS responses.
What HeaderGrade checks
- Presence of
Strict-Transport-Security max-agelength (prefers ≥ 31536000 seconds)- Optional
includeSubDomainsandpreloadtokens
Example
Strict-Transport-Security: max-age=31536000; includeSubDomains
Only enable HSTS when HTTPS works for all paths you care about. Preload has long-lived consequences — read the Chromium preload requirements before submitting.