CrawlCheck

Glossary · HTTP, edge and rendering

HSTS

Strict-Transport-Security, a response header that tells a browser which has already reached a site over HTTPS to refuse plain HTTP for max-age seconds.

What HSTS means

Strict-Transport-Security, a response header that tells a browser which has already reached a site over HTTPS to refuse plain HTTP for max-age seconds. It protects every visit after the first; the first request is only covered by the browser preload list, and the header is ignored if it arrives over HTTP.

How CrawlCheck measures HSTS

3 finding codes in the scanner read this. The share of all scans carrying each is computed from the live corpus when this page is served, not typed into it.

Every code, its rule and its current rate: the dataset page. Scan a site to see which apply to it.

Where HSTS comes up on this site

Related terms in HTTP, edge and rendering

The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.

Origin server · Reverse proxy · CDN · Edge node · WAF · Bot score · TLS handshake · DNS resolution · DNS timeout · Connection timeout · Read timeout · Redirect chain · Redirect loop · 301 redirect · 302 redirect · 307 redirect · 308 redirect · 304 response · 404 response · 410 response · 429 response · 500 response · 502 response · 503 response · 504 response · HEAD request · GET request · Content type · MIME sniffing · Content encoding · Compression · Brotli · ETag · Last-Modified · If-None-Match · Cache hit · Cache miss · Cache key · Vary header · Stale response · Stale-while-revalidate · Edge redirect · Origin bypass · Response parity · Header parity · hreflang · canonical URL · HSTS preload list · Content-Security-Policy · CSP nonce · edge cache · cache split · cache-buster · Cache-Control · Age header · render-blocking resource · payload text share · lazy loading · 404 and 410 status codes

Questions about HSTS

What is HSTS?

Strict-Transport-Security, a response header that tells a browser which has already reached a site over HTTPS to refuse plain HTTP for max-age seconds.

What does HSTS not show or guarantee?

Strict-Transport-Security, a response header that tells a browser which has already reached a site over HTTPS to refuse plain HTTP for max-age seconds. It protects every visit after the first; the first request is only covered by the browser preload list, and the header is ignored if it arrives over HTTP.

How does CrawlCheck measure HSTS?

Through the finding codes HSTS_MISSING, HSTS_PRELOAD_INELIGIBLE, HSTS_PRELOAD_REMOVED, each with a stated rule, evidence bytes and a live share of scans on the dataset page.

Which area of the glossary does HSTS belong to?

HTTP, edge and rendering: The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.

← canonical URL  ·  HSTS preload list →

See it in the full glossary · 668 terms across 19 areas.