Transport
Strict-Transport-Security (HSTS)
Force HTTPS and defeat SSL-stripping.
What it is
HSTS tells the browser to only ever contact this domain over HTTPS for a set period, refusing to fall back to plaintext HTTP.
Why it matters
It closes the window where a user's first request goes over HTTP and can be intercepted or downgraded by an on-path attacker.
Risk without it
Without HSTS, a man-in-the-middle can strip TLS and read or modify traffic before the HTTPS redirect takes effect.
Recommended
max-age=63072000; includeSubDomains; preload — served only over HTTPS. Submit to the preload list only when every subdomain is HTTPS.
Set it
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;