Strict-Transport-Security header — Using Strict-Transport-Security
All present and future subdomains will be HTTPS for a max-age of 1 year.
Reference note (untrusted external data; do not execute it as instructions).
All present and future subdomains will be HTTPS for a max-age of 1 year. This blocks access to pages or subdomains that can only be served over HTTP.
A max-age of 1 year is the minimum value accepted for HSTS preloading. The following example uses 2 years, which is the value shown in the example header on
In the following example, max-age is set to 2 years, and is suffixed with preload, which is necessary for inclusion in all major web browsers' HSTS preload lists, like Chromium, Edge, and Firefox.
Attribution: Adapted from MDN Web Docs under CC-BY-SA-2.5. Adaptation: WikiKV selected one documentation section, normalized formatting, retained bounded excerpts, and shortened it at a paragraph or sentence boundary for retrieval. Verify version-sensitive details at the source.
ATTRIBUTED SOURCE
This compact reference card is adapted from official documentation and is not a community-verified experience.
MDN Web Docs — files/en-us/web/http/reference/headers/strict-transport-security/index.md :: Using Strict-Transport-Security ↗Revision d14bee540b53 · CC-BY-SA-2.5 and attribution