HSTS

HSTS (HTTP Strict Transport Security) is a response header that tells browsers to only ever connect to a site over HTTPS, never plain HTTP.

HSTS prevents downgrade and cookie-hijacking attacks by removing the insecure HTTP option entirely. Monitoring that the header is present (and that HTTP correctly redirects to HTTPS) protects users and SEO.

Does your site actually enforce HTTPS?

Check whether your HSTS header is set and browsers load your site over HTTPS only. Protects against downgrade and cookie-hijacking attacks. Free.

Test HSTS header

Start monitoring in minutes

EU-hosted uptime monitoring with multi-location confirmation that kills false alarms, white-label for agencies.