🔐 HSTS Header Builder
Build a Strict-Transport-Security header that forces browsers to only reach your
site over HTTPS for the given duration.
The header the three controls produce
Everything happens in your browser - the tool builds a string for you to add to your server config. The defaults give:
Strict-Transport-Security: max-age=31536000; includeSubDomains
max-age is seconds, and 31536000 is a year. The clock restarts on
every HTTPS response, so a visitor who comes back monthly is always a fresh year
from forgetting. Two details decide whether it works at all: browsers ignore the
header over plain HTTP, and they ignore it if the certificate did not
validate.
What each option commits you to
- includeSubDomains covers every name under yours, including hosts you forgot. A staging or internal box on HTTP becomes unreachable in any browser that has seen the header - with no way to click through. Inventory your subdomains first.
- The preload flag on its own does nothing. It is your consent to be listed; the listing happens when you submit the domain at hstspreload.org, and the entry then ships inside browser binaries. Getting off the list takes months.
- Raise max-age in stages. A day, then a week, then a year. The mistake is starting at a year and finding a subdomain you cannot serve over HTTPS.
Frequently asked questions
How do I undo HSTS?
Keep serving the header over HTTPS with max-age=0 and each
browser drops its entry next time it visits. You cannot clear it remotely, and
anyone who does not return keeps the old value until it expires. On your own
machine, chrome://net-internals/#hsts deletes a single entry.
Do I still need a redirect from HTTP to HTTPS?
Yes. A first-time visitor, and any client that has never stored your policy, still arrives on port 80. The redirect is also a preload requirement.
What max-age should I use?
A year - 31536000 - once you are confident every hostname serves HTTPS. Two years is only needed if you want headroom above the preload list's one-year minimum; it buys no extra protection.