headers by 0x6a03448f4d
← All headers
Transport

Strict-Transport-Security (HSTS)

Force HTTPS and defeat SSL-stripping.

What it is

HSTS tells the browser to only ever contact this domain over HTTPS for a set period, refusing to fall back to plaintext HTTP.

Why it matters

It closes the window where a user's first request goes over HTTP and can be intercepted or downgraded by an on-path attacker.

Risk without it

Without HSTS, a man-in-the-middle can strip TLS and read or modify traffic before the HTTPS redirect takes effect.

Recommended

max-age=63072000; includeSubDomains; preload — served only over HTTPS. Submit to the preload list only when every subdomain is HTTPS.

Set it

add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;

References