Security Headers

HSTS check

HSTS tells browsers to only ever use HTTPS for your site, so a visitor on public Wi-Fi cannot be quietly downgraded.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We read the Strict-Transport-Security header, its max-age, and whether it includes subdomains.

Why it matters to your business

Even with a redirect, a visitor's first plain-HTTP request can be intercepted on a hostile network. HSTS makes the browser skip that request entirely. A short max-age or missing includeSubDomains leaves gaps an attacker can use.

How to fix it

  1. Send Strict-Transport-Security: max-age=31536000; includeSubDomains once every subdomain works over HTTPS.
  2. Start with a short max-age (for example 300) if you are unsure, and raise it once nothing breaks.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.

Tools that include this check