← All headersResponse header

What is a Strict-Transport-Security header?

HSTS - tells the browser to only ever connect to this site over HTTPS for a given period of time.

HSTS is one of the more important security headers a website can send - once a browser has seen it, that browser will refuse to connect over plain HTTP for the specified duration, closing off a whole class of downgrade and interception attacks. It's also somewhat unforgiving: get the max-age wrong or enable it before HTTPS is fully reliable everywhere on the site, and you can lock visitors out of a domain until the header's lifetime expires, which is exactly why it's worth verifying carefully as part of ongoing uptime and security monitoring rather than setting once and forgetting about it.

Common use case

A bank's website sends Strict-Transport-Security with a long max-age and includeSubDomains, so a returning visitor's browser refuses to even attempt a plain HTTP connection, closing off man-in-the-middle downgrade attacks.

Example

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

History

Standardised in RFC 6797 (2012).

Did you know?

The preload directive lets a site opt into being baked directly into Chrome, Firefox, and other major browsers' shipped HSTS preload lists, protecting even a visitor's very first-ever connection before any header could otherwise be seen.