↑ ↓ select, Enter open, Esc close

Check whether a website sends the HSTS header

Adjust the values, the command updates live
user@server
curl -sI https://example.com/ | grep -i "^strict-transport-security"

Requests the headers of the HTTPS homepage and shows the HSTS directive. It tells the browser to access the domain only via HTTPS for max-age seconds. Empty output means HSTS is not active.

Note: A long max-age with includeSubDomains is practically impossible to roll back quickly. Only enable it once all subdomains reliably support HTTPS.

Also searched as

  • check if hsts is enabled
  • show strict-transport-security header
  • check hsts preload requirements

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.