web / security / HSTS

HSTS policy review guide

Review max-age, includeSubDomains, preload and HTTPS boundaries with synthetic cases. No network request is made.

Strict HTTPS policy boundaries

Keep response header policy distinct from separate preload-list management.

CaseResultKey point
Choose a case to show the matrix.

Why no real header is handled

This page performs no URL fetch, upload, external request, storage, parsing or cookie handling.

Synthetic results do not certify a real site's HSTS or preload status. Confirm delivered headers and enrollment separately.