All checks

HSTS

Whether browsers are told to only ever connect over HTTPS

What it is

HSTS is a response header telling browsers to only ever contact this domain over HTTPS, for a stated length of time. Sites that meet the requirements can also submit themselves to the preload list, which ships inside browsers so even a first-ever request is covered.

Why it matters

Without it, the first request a user makes is usually plain HTTP, and that request can be intercepted before any redirect gets a chance to run. HSTS also stops a user clicking through a certificate warning, which is the step most on-path attacks rely on.

Related checks