Security guide
Strict-Transport-Security is one line of configuration with a long memory. This guide covers what each part of the value does, how to roll it out in steps, and why the preload list is the one decision here you cannot quickly take back.
01 Why it matters
A redirect from HTTP to HTTPS protects everything after it, but not the request that triggered it. That first plain request is visible on the network and can be intercepted before your server ever answers. Strict-Transport-Security removes it: once a browser has seen the header, it upgrades every later request to HTTPS itself, before anything leaves the device.
That memory is also the catch. The browser honours the header for as long as max-age says, and it will not fall back to HTTP in the meantime, even if your certificate expires or a subdomain has never had one. HSTS is therefore a header you grow into rather than switch on at full strength.
02 The value
max-age What it does. Says how many seconds the browser should remember to use HTTPS for this host. Two years, or 63072000 seconds, is the common production value.
Why it matters. A short max-age is the safe way in: start at a few minutes, confirm nothing breaks, then raise it. A long one is the goal, because a visitor who has not been back within the window is unprotected on their next first request.
max-age=63072000 includeSubDomains What it does. Extends the rule to every subdomain of the host that sent the header, including ones that do not exist yet.
Why it matters. Without it, an attacker can work through a subdomain that still answers on HTTP. With it, every subdomain must serve valid HTTPS, so check your internal and legacy hosts before you add it.
max-age=63072000; includeSubDomains preload What it does. Marks the domain as a candidate for the browser preload list, which ships HTTPS-only enforcement inside the browser itself rather than waiting for a first visit.
Why it matters. It closes the very first request for a visitor who has never been to your site. It also means removal takes months and a release cycle of every browser, so treat it as permanent.
max-age=63072000; includeSubDomains; preload 03 Rolling it out
Send the header only from the HTTPS listener. Start with a max-age of a few minutes, then hours, then days, checking each time that every host you own still answers over HTTPS. Add includeSubDomains once you are certain about the subdomains, and only then consider preload.
server { listen 443 ssl; add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always; } Do not send the header over plain HTTP: browsers ignore it there, and it hides mistakes you would rather see. And keep the redirect from HTTP to HTTPS in place. HSTS protects returning visitors, the redirect handles everyone else.
04 Questions
Visitors get a certificate warning they cannot click through, because HSTS removes the exception path. The site is effectively down until the certificate is renewed, which is the main reason to raise max-age in steps.
For the header itself, yes: send max-age=0 and browsers forget the rule as they visit. For the preload list it is a removal request plus the wait until browsers ship the updated list, and that takes months.
If that host is a subdomain of the one sending the header, yes. Every subdomain has to serve valid HTTPS from then on, so inventory them before you add the directive.
It secures the transport, nothing else. It does not affect what a page is allowed to load, how cookies behave or whether your site can be framed. Those are separate headers.
05 In depth
Transport is one layer. These guides cover the ones above it.
What each response header does, which ones your site should send and how to configure them correctly.
The strongest defence against cross-site scripting: which directives to set, how to roll a policy out in report-only mode and how to reach an enforcing policy without breaking your site.
Secure, HttpOnly and SameSite: the cookie attributes that keep a session out of reach of scripts and cross-site requests, with the settings for a typical stack.
How an invisible overlay turns a visitor click into an action on your site, and the two headers that stop it: X-Frame-Options for older clients, frame-ancestors for everything else.
Which part of your URLs travels to other sites when a visitor clicks away: the five policy values that matter, what each one gives up and the one to set by default.
Switch off camera, microphone, geolocation and payment for your site and everything it embeds: the allow-list syntax, and why a feature you did not name is not a feature you turned off.
The records that stop someone sending mail in your name, and the one that keeps your DNS answers honest: what each does and the order to introduce them in.
The file that tells a researcher where to report a vulnerability. Two mandatory fields, ten minutes of work, and the difference between a private report and a public one.
A header that is right today can be gone after the next deploy. Three ways to notice: a cron job with curl, a check in your CI pipeline and a scheduled scan, with what each of them catches and misses.
How a policy changes quietly through deploys, plugins and CDN rules, and how to catch it: a header diff, violation reports through report-to, and what a scan comparison can and cannot show.
Keep reading
Every guide stands on its own, and together they cover what our scanner looks at. Pick the one closest to your next question.
Our free Quickscan reads your live Strict-Transport-Security header alongside the rest of your transport setup, and explains every finding in plain language.