Skip to main content
Security Tools

HSTS Checker

Check whether a website sends the Strict-Transport-Security (HSTS) header.

Enter a domain to check whether it sends the HSTS header.

JustChecker monitors your security headers continuously.

Frequently Asked Questions

HSTS instructs the browser to automatically use https for every future visit to your domain, WITHOUT even attempting an insecure http connection first - closing a brief window of vulnerability that a server-side redirect alone can't fully eliminate.

It's how long (in seconds) the browser should remember to enforce https-only for your domain after this one response - common values range from a few months to a full year (31536000 seconds).

Preloading submits your domain to a hardcoded list built into browsers themselves, enforcing https from the very first visit ever, before any HSTS header has even been received - a stronger, but effectively permanent and hard-to-reverse, commitment.

Yes, this is a real risk - once a browser has cached your HSTS policy, it will refuse any http fallback, so if your certificate later has a genuine problem, visitors who've seen the HSTS header can't even reach an insecure fallback version.

Only if every subdomain of your domain is genuinely ready to be served exclusively over https - including it while a subdomain still relies on plain http will make that subdomain completely inaccessible to browsers that have cached the policy.

Yes - any unencrypted connection is vulnerable to interception and manipulation in transit, regardless of the specific content, so HSTS remains valuable general hardening for any production website.
Share this tool: