Skip to content
SilktideHelp

Strict Transport Security

Silktide checks that your encrypted pages tell browsers to always use the secure version of your website. This instruction, called Strict Transport Security, prevents browsers from ever connecting over an unencrypted connection, even when a visitor types a plain address or follows an old link.

The instruction is an sent with each page over :

Strict-Transport-Security: max-age=31536000

Why this matters

Even a website served entirely over HTTPS usually accepts one unencrypted request first: the visitor types example.com, the browser tries http://, and the server redirects to https://. That single unencrypted hop is enough for an attacker on the same network to intercept the connection and keep the visitor on a fake or tampered version of the site - a man-in-the-middle attack.

Strict Transport Security (HSTS) closes the gap. Once a browser has seen the header, it upgrades every future request to HTTPS by itself, for as long as the max-age says, so the vulnerable first request never happens again.

How to fix it

  1. Make sure your whole website works over HTTPS first - once HSTS is active, browsers will refuse the unencrypted version entirely.
  2. Configure your web server, hosting platform, or to send the Strict-Transport-Security header on all HTTPS responses. Many platforms have a one-click HSTS setting.
  3. Set a meaningful max-age in seconds. Start small (such as 86400, one day) if you want a trial period, then raise it to a year (max-age=31536000) once you are confident.
  4. Optionally add includeSubDomains to cover every subdomain, but only if all of them support HTTPS.

How Silktide tests this

  1. Check each page served over HTTPS for a Strict-Transport-Security header with a non-empty value.
  2. Report the page if the header is missing.
  3. Pages served over unencrypted connections are skipped, because browsers ignore this header there - securing those pages is covered by the SSL encryption check.

Troubleshooting

I set the header but the check still fails

Confirm the header is sent by the exact pages being scanned, not just the home page. You can see a page's response headers in your browser's developer tools, under the Network tab.

Can HSTS lock visitors out?

If you enable HSTS and later break your HTTPS setup (for example, an expired certificate), browsers that remember the header will refuse to fall back to the unencrypted site until max-age expires. This is by design - keep your certificate renewals automated.

Learn more

Last updated

Was this page helpful?

Strict Transport Security | Silktide Help