HSTS Badge
HSTS tells browsers to use HTTPS for your site automatically on every later visit. This badge reads your Strict-Transport-Security header and reports whether it is on, how long browsers are told to remember it, and whether it meets the preload list's rules.
Live preview
Checked live by A2ZShowing the badge for a2z.tools. Enter your domain to see yours.
Embed code
The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".
Works with
How it works
A2Z requests your home page over HTTPS and parses the Strict-Transport-Security response header into its max-age, includeSubDomains and preload directives, exactly as RFC 6797 defines them. A header on a plain-HTTP response is ignored because browsers ignore it there too. A max-age under 180 days is reported as short, and "preload" is only shown when the header carries both preload and includeSubDomains, because the preload list requires both.
What is checked
- Enabled: a Strict-Transport-Security header on the HTTPS response with max-age > 0 (RFC 6797 section 6.1)
- Short max-age: under 15,552,000 seconds (180 days); max-age=0 switches HSTS off
- "preload" shown only when preload and includeSubDomains are both present (hstspreload.org requirements)
Worked examples
Preload-ready header
Inputs: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Result: Green: "enabled, preload"
Two years exceeds the one-year preload minimum.
A cautious first step
Inputs: Strict-Transport-Security: max-age=86400
Result: Amber: "enabled, short max-age"
One day is a safe test value but gives little lasting protection.
Limitations
- Does not check whether the domain is actually on the browsers' preload list.
- Reads the header from the home page only.
- Subdomains are not tested even when includeSubDomains is set.
Where publishers use it
- Security-conscious SaaS marketing sites
- Developer blogs documenting their hardening
- Agency hand-over reports
Questions
What max-age should I use?
Start short, for example a day, while you confirm everything works over HTTPS, then raise it to at least six months. The preload list asks for one year (31,536,000 seconds).
What does HSTS protect against?
It stops a browser from loading your site over plain HTTP after its first visit, which blocks SSL-stripping downgrade attacks on public Wi-Fi.
Is preload required?
No. Preloading adds your domain to browsers' built-in list so even the first visit is protected. It is optional and slow to undo, so the badge simply reports it.
Why is my header not detected?
HSTS is only honoured on HTTPS responses. A2Z reads the header from https://your-domain/ after redirects; a header sent only on the HTTP response does not count.
Sources
- RFC 6797 - HTTP Strict Transport Security (HSTS) - IETF
- HSTS preload list submission requirements - hstspreload.org (Chromium) . One-year max-age, includeSubDomains and preload.
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools HSTS Badge https://a2z.tools/hsts-checker
<a href="https://a2z.tools/hsts-checker">A2Z Tools HSTS Badge</a>
[A2Z Tools HSTS Badge](https://a2z.tools/hsts-checker)
HSTS Badge by A2Z Tools - https://a2z.tools/hsts-checker
Related widgets
-
Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.
-
Counts how many of six key HTTP security headers your site sends - e.g. "5 / 6".
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
A badge counting down the days until your SSL certificate expires.
-
Shows whether your domain publishes an SPF record and how it ends (-all, ~all).
-
Shows your domain's DMARC policy - p=reject, p=quarantine or p=none.