HSTS Preload Checker
Check a Strict-Transport-Security header against the browser preload list requirements, see what each directive commits you to, and get a staged rollout plan.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
The gap HSTS closes
A user who types a domain without a scheme makes a plaintext HTTP request first. A redirect to HTTPS closes the connection safely, but the first request already travelled in the clear and could have been intercepted and redirected somewhere else entirely. Strict-Transport-Security tells the browser to use HTTPS for that domain for a given period without asking, which removes the plaintext request for every visit after the first. Preloading removes it for the first visit too by shipping the domain in the browser itself.
Preloading is a commitment, not a setting
Submission to the preload list requires a max-age of at least one year, the includeSubDomains directive and the preload token, plus a valid certificate and an HTTPS redirect on the apex. Once a domain is on the list, every browser that ships it will refuse any plaintext connection to that domain or any subdomain, permanently until removal propagates, and removal takes months to reach users because it waits for browser releases. A subdomain that cannot serve HTTPS becomes unreachable with no way to override it.
Stage the rollout
The safe sequence is to serve a short max-age of a few minutes and confirm nothing breaks, raise it to a day, then a month, then a year, adding includeSubDomains only once every subdomain including internal and legacy ones has a valid certificate. Only then add the preload token and submit. Skipping straight to a one year includeSubDomains header is how an internal tool on a subdomain becomes unreachable for everyone who visited the main site.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
What max-age should I use?
Two years is common for an established site and one year is the preload minimum. Start at a few minutes while testing, because a long max-age is difficult to undo: browsers honour the cached value until it expires regardless of what you serve afterwards.
How do I undo HSTS if something breaks?
Serve max-age=0, which clears it for anyone who visits again. That does not help users who do not return before the old value expires, and it does nothing at all for a preloaded domain, where removal requires a submission and months of browser releases.
Does includeSubDomains affect internal subdomains?
Yes, every subdomain without exception, including internal tools, staging environments and anything on a legacy device. Each one must serve valid HTTPS or become unreachable in browsers that have seen the header.
Is preloading worth it?
For a domain that is HTTPS only and will remain so, yes: it closes the first visit gap that HSTS alone cannot. For a domain with subdomains of uncertain status, the risk of making something unreachable for months outweighs the benefit.
Does HSTS protect against a compromised certificate?
No. It ensures HTTPS is used but says nothing about which certificate is acceptable. Certificate Transparency and CAA records address that. HSTS defends against downgrade and stripping attacks specifically.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste your HSTS header or build one to check preload eligibility and understand the commitment.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.