Skip to main content
Book 07 · SecurityPage 16 of 50

HSTS

HTTP Strict Transport Security

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/hsts

In short

HSTS is a security header that tells browsers to connect to a site only over HTTPS for a set period, blocking insecure HTTP connections and downgrade attacks.

What is HSTS?

HTTP Strict Transport Security, or HSTS, is a response header a website sends to say: from now on, only talk to me over HTTPS. After a browser sees the Strict-Transport-Security header, it automatically upgrades every future http:// link and typed address for that domain to https:// before any request leaves the machine. It also stops users from clicking through certificate warnings on that site.

The header has a max-age value in seconds, often one or two years, that tells the browser how long to remember the rule, and an optional includeSubDomains flag that applies it to every subdomain. The browser only accepts the header when it arrives over a valid HTTPS connection. Because the very first visit could still happen over plain HTTP, browsers also ship a built-in HSTS preload list: sites that meet the requirements and add the preload flag can be included, so browsers use HTTPS for them even on the first visit.

Without HSTS, a user who types example.com usually makes a plain HTTP request first and is then redirected to HTTPS, and an attacker on the same public Wi-Fi can intercept that first request and keep the victim on an unencrypted connection, a technique called SSL stripping. HSTS removes that window. It is like a standing rule at a bank that large withdrawals are only handled at the secure counter: once the rule is on file, nobody can talk a teller into using the unlocked side door.

HSTS is often confused with HTTPS itself or with an HTTP-to-HTTPS redirect. HTTPS provides the encryption, and a redirect sends users to it after an insecure request has already been made, while HSTS makes the browser refuse to use HTTP at all for that site. Be careful with includeSubDomains and preloading, because every subdomain must then support HTTPS, and removing a site from the preload list takes months.

Key takeaways

  • HSTS tells browsers to use only HTTPS for a site for a set period.
  • It is sent in the Strict-Transport-Security response header over HTTPS.
  • It blocks SSL stripping and other downgrade attacks after the first visit.
  • The preload list protects even the first visit for sites that opt in.
  • Test with a short max-age before committing to long values and preloading.

Example

Checking and setting the HSTS headerbash
# Check whether a site sends the HSTS header
curl -sI https://example.com | grep -i strict-transport-security

# A typical strong policy: two years, all subdomains, eligible for preloading
# Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

# Start with a short max-age (5 minutes) while testing
# Strict-Transport-Security: max-age=300

Readers ask

Is an HTTP to HTTPS redirect enough without HSTS?

No. The redirect only happens after the browser has already sent an insecure request, which an attacker on the network can intercept. HSTS makes the browser skip plain HTTP entirely on later visits.

What is the HSTS preload list?

It is a list of domains built into major browsers that are always loaded over HTTPS, even on the first visit. A site can apply by sending an HSTS header with a long max-age, includeSubDomains, and preload, and by serving HTTPS on all its subdomains.

What happens if my certificate expires on an HSTS site?

Browsers block the site with an error that users cannot click through, because HSTS forbids bypassing certificate warnings. Automate certificate renewal before enabling a long max-age.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings