HTTPS

HSTS Checker: Test Strict-Transport-Security Online

An HSTS checker confirms whether an HTTPS website sends the Strict-Transport-Security header and reviews its directives. Flux8Shield also checks certificate validity and HTTP-to-HTTPS behavior, helping distinguish a missing HSTS policy from a broader TLS or redirect problem.

September 27, 2026 · 6 min read

Run the free hsts header checker

Enter a public website URL. The passive scan returns a security report in seconds—no account or installation required.

Scan a website free →

What does the HSTS header do?

Strict-Transport-Security tells a browser to use HTTPS for future connections to a hostname. Once the browser has received the policy over a valid HTTPS connection, it upgrades later HTTP attempts before sending them across the network.

HSTS also prevents users from bypassing certificate warnings for a remembered HSTS host. That makes certificate monitoring and reliable renewal especially important.

What should an HSTS checker verify?

The key value is max-age, expressed in seconds. A short value is useful during rollout, while mature deployments commonly use one year. includeSubDomains extends the policy to every subdomain, and preload signals an intention to join browser preload lists.

The header must be delivered over HTTPS. Browsers ignore it over HTTP because an attacker could otherwise inject or weaken an HSTS policy before a secure connection exists.

How do I enable HSTS without breaking subdomains?

Inventory every subdomain before adding includeSubDomains. Old services, vendor endpoints, development hosts, or forgotten DNS records may still lack valid HTTPS and would become unreachable in compliant browsers.

Begin with a short max-age on the primary host, validate redirects and certificates, then increase the duration. Add includeSubDomains and preload only after the entire domain tree is ready for permanent HTTPS.

Frequently asked questions

Is an HTTPS redirect the same as HSTS?

No. A redirect happens after an HTTP request reaches the server. HSTS lets a returning browser upgrade the request before sending it.

What max-age should I use?

Start short during testing. A mature preload-ready policy requires at least 31536000 seconds and includeSubDomains.

Can I send HSTS over HTTP?

You can send the text, but browsers deliberately ignore it. The policy must arrive over a valid HTTPS connection.

Related security checks