๐ HSTS Header Builder
Strict-Transport-Security: max-age=31536000; includeSubDomains
Build a Strict-Transport-Security (HSTS) header, which tells browsers to always connect to your site over HTTPS, by setting the max-age duration and the includeSubDomains and preload options.
How to use
- Enter the max-age (in seconds) โ how long browsers should remember this policy.
- Enable includeSubDomains if the policy should also apply to subdomains, and preload if you plan to submit the site to the browser preload list.
- The assembled HSTS header string is shown automatically.
How the calculation works
Strict-Transport-Security (HSTS), defined in RFC 6797, is an HTTP response header that tells a browser to use HTTPS for every future connection to your site. Once a browser has seen the header, it rewrites any http:// request for that domain to https:// on its own, before contacting the server at all. That matters because it closes off SSL stripping, where an attacker intercepts and tampers with that very first plain HTTP request. A server-side redirect alone cannot help here: the first round trip still happens in the clear before the redirect is received. max-age is how many seconds the browser remembers the instruction. includeSubDomains extends the rule to every subdomain. preload signals an intention to be added to the list of domains built into major browsers that are forced to HTTPS from the very first request โ a browser-vendor mechanism that is not itself part of RFC 6797.
Worked example
A one-year policy that also covers subdomains Strict-Transport-Security: max-age=31536000; includeSubDomains 31536000 seconds is 60 ร 60 ร 24 ร 365, exactly one year. A browser receiving this will use HTTPS for example.com and all its subdomains for the next year. The window refreshes on each visit, so regular visitors stay covered continuously. A common approach when starting out is to set something short such as max-age=600 (ten minutes), confirm nothing breaks, and then raise it.
Things to be aware of
- Confirm that your whole site, subdomains included, works over HTTPS before enabling this. Any HTTP-only page becomes unreachable for the duration of max-age.
- includeSubDomains applies to every subdomain without exception โ take care not to overlook internal ones that are not yet on HTTPS.
- Preload list submission is a separate process, and removal takes time. It is not something you can reverse quickly.
- The header only takes effect when sent over HTTPS. Browsers correctly ignore it when it arrives over plain HTTP.
FAQ
What is Strict-Transport-Security?
It's an HTTP response header defined by RFC 6797. Once a browser receives it, that browser automatically upgrades all future connections to the site to HTTPS for the specified duration, preventing man-in-the-middle downgrade attacks to plain HTTP.
What value should I use for max-age?
It's the number of seconds the browser should remember this setting. 31536000 (one year) is common, but it's recommended to start with a short value for testing and gradually increase it once you've confirmed everything works over HTTPS.
What does the preload option do?
preload signals intent to be added to the HSTS preload list built into major browsers, which forces HTTPS from a visitor's very first request โ even before they've seen your header. Actual inclusion requires a separate submission and review process, and removal from the list afterward can take a long time, so enable it with that in mind.