🔐 HSTS Header Builder

Build a Strict-Transport-Security header that forces browsers to only reach your site over HTTPS for the given duration.

The header the three controls produce

Everything happens in your browser - the tool builds a string for you to add to your server config. The defaults give:

Strict-Transport-Security: max-age=31536000; includeSubDomains

max-age is seconds, and 31536000 is a year. The clock restarts on every HTTPS response, so a visitor who comes back monthly is always a fresh year from forgetting. Two details decide whether it works at all: browsers ignore the header over plain HTTP, and they ignore it if the certificate did not validate.

What each option commits you to

HSTS cannot protect a browser's very first visit to your site, because it has not received the header yet. Closing that gap is the whole point of the preload list.

Frequently asked questions

How do I undo HSTS?

Keep serving the header over HTTPS with max-age=0 and each browser drops its entry next time it visits. You cannot clear it remotely, and anyone who does not return keeps the old value until it expires. On your own machine, chrome://net-internals/#hsts deletes a single entry.

Do I still need a redirect from HTTP to HTTPS?

Yes. A first-time visitor, and any client that has never stored your policy, still arrives on port 80. The redirect is also a preload requirement.

What max-age should I use?

A year - 31536000 - once you are confident every hostname serves HTTPS. Two years is only needed if you want headroom above the preload list's one-year minimum; it buys no extra protection.