HSTS Badge

HSTS tells browsers to use HTTPS for your site automatically on every later visit. This badge reads your Strict-Transport-Security header and reports whether it is on, how long browsers are told to remember it, and whether it meets the preload list's rules.

Website & Security SVG badge Checked by A2Z server Free · no ads

Customize your badge

The badge is checked for this domain. Enter the site you will show it on.
Style
Colours
Size

Live preview

Checked live by A2Z
HSTS Badge for a2z.tools

Showing the badge for a2z.tools. Enter your domain to see yours.

Embed code

The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".

Works with

How it works

A2Z requests your home page over HTTPS and parses the Strict-Transport-Security response header into its max-age, includeSubDomains and preload directives, exactly as RFC 6797 defines them. A header on a plain-HTTP response is ignored because browsers ignore it there too. A max-age under 180 days is reported as short, and "preload" is only shown when the header carries both preload and includeSubDomains, because the preload list requires both.

What is checked

  • Enabled: a Strict-Transport-Security header on the HTTPS response with max-age > 0 (RFC 6797 section 6.1)
  • Short max-age: under 15,552,000 seconds (180 days); max-age=0 switches HSTS off
  • "preload" shown only when preload and includeSubDomains are both present (hstspreload.org requirements)

Worked examples

Preload-ready header

Inputs: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

Result: Green: "enabled, preload"

Two years exceeds the one-year preload minimum.

A cautious first step

Inputs: Strict-Transport-Security: max-age=86400

Result: Amber: "enabled, short max-age"

One day is a safe test value but gives little lasting protection.

Limitations

  • Does not check whether the domain is actually on the browsers' preload list.
  • Reads the header from the home page only.
  • Subdomains are not tested even when includeSubDomains is set.

Where publishers use it

  • Security-conscious SaaS marketing sites
  • Developer blogs documenting their hardening
  • Agency hand-over reports

Questions

What max-age should I use?

Start short, for example a day, while you confirm everything works over HTTPS, then raise it to at least six months. The preload list asks for one year (31,536,000 seconds).

What does HSTS protect against?

It stops a browser from loading your site over plain HTTP after its first visit, which blocks SSL-stripping downgrade attacks on public Wi-Fi.

Is preload required?

No. Preloading adds your domain to browsers' built-in list so even the first visit is protected. It is optional and slow to undo, so the badge simply reports it.

Why is my header not detected?

HSTS is only honoured on HTTPS responses. A2Z reads the header from https://your-domain/ after redirects; a header sent only on the HTTP response does not count.

What max-age should I use?

Start small (for example 300 seconds) while you confirm every subdomain works over HTTPS, then raise it. The hstspreload.org submission requirements ask for at least one year (31536000 seconds) with includeSubDomains and preload. Removing HSTS later only takes effect as the max-age stored in browsers expires.

Sources

  1. RFC 6797 - HTTP Strict Transport Security (HSTS) - IETF
  2. HSTS preload list submission requirements - hstspreload.org (Chromium) . One-year max-age, includeSubDomains and preload.

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools HSTS Badge
https://a2z.tools/hsts-checker
  • HTTPS Badge

    Website & Security SVG badge

    Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.

    Get code
  • Security Headers Badge

    Website & Security SVG badge

    Counts how many of six key HTTP security headers your site sends - e.g. "5 / 6".

    Get code
  • SSL Certificate Badge

    Website & Security SVG badge

    A live badge showing that your SSL certificate is valid, trusted and how many days it has left.

    Get code
  • SSL Expiry Badge

    Website & Security SVG badge

    A badge counting down the days until your SSL certificate expires.

    Get code
  • SPF Record Badge

    Website & Security SVG badge

    Shows whether your domain publishes an SPF record and how it ends (-all, ~all).

    Get code
  • DMARC Policy Badge

    Website & Security SVG badge

    Shows your domain's DMARC policy - p=reject, p=quarantine or p=none.

    Get code

Preview