HTTP Strict Transport Security
HSTS · A response header that tells the browser to connect to a site only over an encrypted connection (HTTPS) for a set period.
- 01
Why it matters
Without HSTS a visitor's first request can go out unencrypted, and someone on a shared network can hijack the connection. Once the header is received, the browser refuses to connect to the site without encryption. If all subdomains serve HTTPS, the header can be set broadly and for a long period.
- 02
Example
A visitor on café Wi-Fi types only the domain name. Because the site sent HSTS earlier, the browser goes straight to an encrypted connection and the interception attempt fails.
- 03
Common mistake
Turning on long-lived HSTS for all subdomains while one of them does not support HTTPS. That subdomain becomes unreachable for visitors; try short durations first.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.