web / security / HSTS
HSTS policy review guide
Review max-age, includeSubDomains, preload and HTTPS boundaries with synthetic cases. No network request is made.
web / security / HSTS
Review max-age, includeSubDomains, preload and HTTPS boundaries with synthetic cases. No network request is made.
Keep response header policy distinct from separate preload-list management.
| Case | Result | Key point |
|---|---|---|
| Choose a case to show the matrix. | ||
This page performs no URL fetch, upload, external request, storage, parsing or cookie handling.
Synthetic results do not certify a real site's HSTS or preload status. Confirm delivered headers and enrollment separately.