[ GF.dev ] All Tools →

HSTS Configuration Check

HTTP Strict Transport Security (HSTS) tells browsers that they should only ever connect to your website via HTTPS. This tool verifies if the header is present and configured correctly to prevent protocol downgrade attacks.

Ready to scan...

Frequently Asked Questions

What is the risk of missing HSTS?

Users might inadvertently connect via HTTP first, allowing attackers to intercept the connection before it switches to HTTPS.

What is 'includeSubDomains'?

This flag ensures that HSTS protection applies to all subdomains (e.g., blog.yoursite.com) as well as the main domain.

Learn More

The Complete Guide to HTTP Security Headers (Guide)
What is HSTS and How to Configure It Properly · The Complete Guide to HTTP Security Headers
How to Get an A+ on SSL Labs (Step-by-Step) · SSL/TLS Configuration Guide: Securing Your Web Server from Scratch