Strict Transport Security
Silktide checks that your encrypted pages tell browsers to always use the secure version of your website. This instruction, called Strict Transport Security, prevents browsers from ever connecting over an unencrypted connection, even when a visitor types a plain address or follows an old link.
The instruction is an sent with each page over :
Strict-Transport-Security: max-age=31536000
Why this matters
Even a website served entirely over HTTPS usually accepts one unencrypted
request first: the visitor types example.com, the browser tries http://,
and the server redirects to https://. That single unencrypted hop is
enough for an attacker on the same network to intercept the connection and
keep the visitor on a fake or tampered version of the site - a
man-in-the-middle attack.
Strict Transport Security (HSTS) closes the gap. Once a browser has seen the
header, it upgrades every future request to HTTPS by itself, for as long as
the max-age says, so the vulnerable first request never happens again.
How to fix it
- Make sure your whole website works over HTTPS first - once HSTS is active, browsers will refuse the unencrypted version entirely.
- Configure your web server, hosting platform, or to send the
Strict-Transport-Securityheader on all HTTPS responses. Many platforms have a one-click HSTS setting. - Set a meaningful
max-agein seconds. Start small (such as86400, one day) if you want a trial period, then raise it to a year (max-age=31536000) once you are confident. - Optionally add
includeSubDomainsto cover every subdomain, but only if all of them support HTTPS.
How Silktide tests this
- Check each page served over HTTPS for a
Strict-Transport-Securityheader with a non-empty value. - Report the page if the header is missing.
- Pages served over unencrypted connections are skipped, because browsers ignore this header there - securing those pages is covered by the SSL encryption check.
Troubleshooting
I set the header but the check still fails
Confirm the header is sent by the exact pages being scanned, not just the home page. You can see a page's response headers in your browser's developer tools, under the Network tab.
Can HSTS lock visitors out?
If you enable HSTS and later break your HTTPS setup (for example, an expired
certificate), browsers that remember the header will refuse to fall back to
the unencrypted site until max-age expires. This is by design - keep your
certificate renewals automated.