Reference

What is HSTS?

HSTS is a response header telling browsers to use HTTPS for a domain for a stated period, refusing to connect over HTTP even if a user types it. It closes the window where a first insecure request can be intercepted.

Also called: Strict-Transport-Security

What it prevents

A redirect from HTTP to HTTPS still involves one insecure request, which can be intercepted on a hostile network. With HSTS remembered, the browser never makes that request in the first place.

Deploying it safely

  1. Confirm HTTPS works everywhere, including every subdomain you intend to include
  2. Start with a short max-age to verify nothing breaks
  3. Increase to a year once confident
  4. Consider includeSubDomains only when every subdomain genuinely supports HTTPS

The commitment worth understanding

HSTS is remembered by the browser for the duration you set. If HTTPS breaks during that period, affected visitors cannot reach the site at all — which is why the max-age is raised gradually rather than set to a year on day one.

Where this is covered in depth

A definition can only go so far. Technical SEO, in the order the problems actually block you covers this properly — 4 minutes, free, no email required.

Who wrote this

Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan. These definitions come from client work rather than from a content brief — where an entry describes a mistake, it is usually one found on a real site. More about how I work.

Related terms

All 184 terms in the glossary →

Want this handled rather than explained?

Send the brief and you get a reply within one business day — either questions, or a scoping call. If your project is not something I should take on, I will say so then.

Response
Replies within 1 business day
Hours
Mon–Fri, 09:00–18:00 PKT — overlaps 05:00–14:00 UK, 00:00–09:00 US Eastern
Booking
Booking projects from October 2026
WhatsApp — opens a chat with +92 346 5348466 in a new tab