No HSTS Header: What It Means and How to Enable HSTS

Your scan flagged that the site does not send an HSTS header (or uses a weak, short one). Without it, a browser can be quietly pushed from HTTPS down to plain HTTP on someone's first visit. Enabling HSTS is a single response header, and this page walks you through doing it safely.

Run the free scan

One free scan, no login. This check runs alongside DNS, email, TLS, headers, exposed files and known CVEs.

What an HSTS header actually does

HSTS stands for HTTP Strict Transport Security. It is a single response header that tells the browser that, for this site, it should always use HTTPS and never fall back to plain HTTP. Once a browser has seen it, the browser remembers the rule and upgrades every future request to HTTPS on its own (MDN, Strict-Transport-Security).

BadgerScan reported this because the outside view of your site shows either no Strict-Transport-Security header at all, or one with a very short lifetime. A short lifetime is treated as weak because the protection expires quickly and has to be renewed on every visit to stay useful.

The header looks like Strict-Transport-Security: max-age=31536000; includeSubDomains. The max-age value is measured in seconds, and 31536000 is one year. That number is how long the browser will keep enforcing HTTPS after it last saw the header.

Why it is worth fixing

Without HSTS, a visitor who types your address or follows an old link can start on plain http:// before any redirect kicks in. On an untrusted network, someone positioned between the visitor and your server can intercept that first unencrypted request and keep the visitor on HTTP, a move known as a downgrade. HSTS closes that gap by making the browser refuse HTTP up front (OWASP, HTTP Strict Transport Security Cheat Sheet).

This is a medium-severity item, not an emergency. Your site can still work fine over HTTPS today. HSTS simply removes the small first-visit window where a downgrade is possible, and it is a quick, low-effort header to add. If you are not sure your site already redirects HTTP to HTTPS, a quick free scan will show you the outside view in plain language.

How to enable HSTS, step by step

The order here matters. HSTS makes HTTPS mandatory, so confirm HTTPS is fully working before you turn it on. Then add the header at whichever layer you control: your web server, your CDN, or a plugin.

  • Confirm HTTPS works everywhere first. Every page, image, and script should load over https:// with a valid certificate and no mixed-content warnings, and plain HTTP should already redirect to HTTPS.
  • Add the response header Strict-Transport-Security: max-age=31536000; includeSubDomains. Set it in your web server config, your CDN or hosting dashboard, or with a security-headers plugin. Most managed hosts and CDNs have a one-line setting or toggle for this.
  • Only include includeSubDomains once every subdomain (for example www, shop, blog) is served over HTTPS. If a subdomain is still on HTTP, leave that part off until it is fixed, or you will make that subdomain unreachable.
  • Leave preload off for now. Only add ; preload when you are ready to commit to HTTPS-only permanently and you submit your domain to the browser preload list. It is hard to reverse, so treat it as a deliberate later step, not part of the initial setup.
  • Re-run your scan to confirm the outside view now shows the header. You can double-check with the security headers checker.

How to verify (and one thing to be careful with)

After you deploy, load your site fresh and check that the Strict-Transport-Security header appears on the HTTPS response with the year-long max-age. If it is missing, the header may only be set on certain paths, or it may have been added over HTTP, which browsers ignore.

The one thing to be careful with is turning on HSTS before HTTPS is solid everywhere. Because the browser will then refuse plain HTTP for the full max-age window, a broken certificate or a subdomain still on HTTP can lock visitors out until it is fixed. Get HTTPS clean first, keep max-age at one year, and add includeSubDomains and preload only when you are sure.

Check your security headers in under a minute

See whether your site sends an HSTS header, and what else is missing from the outside view. Run the free BadgerScan scan for a plain-language report. No login, no software to install.

Run a free security scan

Frequently asked questions

Is a short HSTS max-age better than none?

Slightly, but it is still flagged as weak. A short max-age expires so quickly that the browser stops enforcing HTTPS between visits, which leaves the downgrade window open. Use max-age=31536000 (one year) so the protection actually sticks.

Will enabling HSTS break my site?

Not if HTTPS already works everywhere. HSTS only tells browsers to use the HTTPS you already have. Problems appear when a certificate is broken or a subdomain is still on HTTP, so confirm those are clean before adding the header, and hold off on includeSubDomains until every subdomain is HTTPS.

Do I need the preload option?

No, not to fix this finding. Plain Strict-Transport-Security: max-age=31536000; includeSubDomains is enough. Adding ; preload and submitting to the preload list is a permanent, HTTPS-only commitment that is hard to undo, so only do it once you are certain.

How do I confirm HSTS is now working?

Re-run the free BadgerScan scan and check the outside view for the Strict-Transport-Security header, or use the security headers checker tool. If it shows up on your HTTPS response with a one-year max-age, you are set.

Sources

  1. MDN, Strict-Transport-Security
  2. OWASP, HTTP Strict Transport Security Cheat Sheet

More from CyberBadger

BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.

Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.