HSTS Badge

HSTS tells browsers to use HTTPS for your site automatically on every later visit. This badge reads your Strict-Transport-Security header and reports whether it is on, how long browsers are told to remember it, and whether it meets the preload list's rules.

Website & Security SVG badge Checked by A2Z server Free · no ads

Customize your badge

The badge is checked for this domain. Enter the site you will show it on.
Style
Colours
Size

Live preview

Checked live by A2Z
HSTS Badge for a2z.tools

Showing the badge for a2z.tools. Enter your domain to see yours.

Embed code

The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".

Works with

How it works

A2Z requests your home page over HTTPS and parses the Strict-Transport-Security response header into its max-age, includeSubDomains and preload directives, exactly as RFC 6797 defines them. A header on a plain-HTTP response is ignored because browsers ignore it there too. A max-age under 180 days is reported as short, and "preload" is only shown when the header carries both preload and includeSubDomains, because the preload list requires both.

What is checked

  • Enabled: a Strict-Transport-Security header on the HTTPS response with max-age > 0 (RFC 6797 section 6.1)
  • Short max-age: under 15,552,000 seconds (180 days); max-age=0 switches HSTS off
  • "preload" shown only when preload and includeSubDomains are both present (hstspreload.org requirements)

Worked examples

Preload-ready header

Inputs: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

Result: Green: "enabled, preload"

Two years exceeds the one-year preload minimum.

A cautious first step

Inputs: Strict-Transport-Security: max-age=86400

Result: Amber: "enabled, short max-age"

One day is a safe test value but gives little lasting protection.

Limitations

  • Does not check whether the domain is actually on the browsers' preload list.
  • Reads the header from the home page only.
  • Subdomains are not tested even when includeSubDomains is set.

Where publishers use it

  • Security-conscious SaaS marketing sites
  • Developer blogs documenting their hardening
  • Agency hand-over reports

Questions

What max-age should I use?

Start short, for example a day, while you confirm everything works over HTTPS, then raise it to at least six months. The preload list asks for one year (31,536,000 seconds).

What does HSTS protect against?

It stops a browser from loading your site over plain HTTP after its first visit, which blocks SSL-stripping downgrade attacks on public Wi-Fi.

Is preload required?

No. Preloading adds your domain to browsers' built-in list so even the first visit is protected. It is optional and slow to undo, so the badge simply reports it.

Why is my header not detected?

HSTS is only honoured on HTTPS responses. A2Z reads the header from https://your-domain/ after redirects; a header sent only on the HTTP response does not count.

Sources

  1. RFC 6797 - HTTP Strict Transport Security (HSTS) - IETF
  2. HSTS preload list submission requirements - hstspreload.org (Chromium) . One-year max-age, includeSubDomains and preload.

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools HSTS Badge
https://a2z.tools/hsts-checker

Preview