Check whether a website sends the HSTS header
check if hsts is enabled | show strict-transport-security header | check hsts preload requirements | curl | hsts | https | headerscurl -sI https://example.com/ | grep -i "^strict-transport-security"Requests the headers of the HTTPS homepage and shows the HSTS directive. It tells the browser to access the domain only via HTTPS for max-age seconds. Empty output means HSTS is not active.
Note: A long max-age with includeSubDomains is practically impossible to roll back quickly. Only enable it once all subdomains reliably support HTTPS.
Also searched as
- check if hsts is enabled
- show strict-transport-security header
- check hsts preload requirements