// free tool

HSTS & Preload Eligibility Checker

Is your site truly https-only, or just redirecting? This free HSTS checker reads your Strict-Transport-Security header in seconds and tells you how long browsers are told to stay on https, whether subdomains are covered, and how close the domain is to the browser preload list.

Enter your main domain, such as example.com. A subdomain like www.example.com still shows you the header, but the preload list only ever accepts a main domain, so the eligibility answers would not be yours. .

This checked one URL, once.

VitalSentinel Inspector audits the whole page in one pass: this check plus every other technical SEO and performance issue on it, scored and ordered by what to fix first.

Free plan, no credit card

What it checks

  • Grades how long the promise lasts against the 180-day mark and the one-year minimum that preloading requires, and flags anything in the header that is not part of HSTS
  • Catches the header sent on the http address, where browsers ignore it, and sent twice, where browsers act on the first copy only
  • Follows the redirects from http:// and reports whether you reach https:// before visitors are sent to another host
  • Tests every preloading requirement it can see, and looks up whether your domain is already on the preload list browsers ship with

What it does not

  • List membership comes from a lookup at hstspreload.org, which has no SLA. When it does not answer, the report covers your header only and list status reads Unknown
  • It cannot check that every subdomain serves https, and that is the requirement that takes sites offline
  • It checks configuration, not your application, and it judges your certificate only by the fact that our own client accepted it. A browser applies stricter rules
  • The base domain is taken as the last two parts of the host, so example.co.uk reads as co.uk. On a domain like that the list lookup asks about the wrong site and the eligibility rows are not yours

Questions

What max-age should I use?
Start at 300 seconds while you confirm nothing breaks, then a few days, then six months. One year is required only if you intend to preload. Each step is a commitment you cannot take back quickly: for that long, visitors simply cannot reach you over plain http.
How do I undo HSTS if something breaks?
Send max-age=0 and browsers drop the rule on their next visit. That does nothing about a preload entry: getting off the list is a manual request through hstspreload.org, and it then waits for new browser versions to reach everyone.
Is includeSubDomains safe to add?
Only once every subdomain serves https, including internal ones that never see public traffic. It has no exceptions and no way to leave one out. The usual casualty is some host nobody has thought about in years.
Why is my Strict-Transport-Security header being ignored?
The usual cause is that it was set on a plain http page. Browsers ignore Strict-Transport-Security unless it arrives over https, so a header you applied everywhere does nothing on the http side. It also happens when the header is sent twice, because browsers read only the first copy.

More free tools

Fair use, and how to recognize us

5 per minute · 25 per hour · 100 per day per IP (per /64 for IPv6), plus a per-site limit

Every request these tools make sends this user agent, including the ones that load a page in a real browser. What a run records is set out in our privacy policy.

Mozilla/5.0 (compatible; VitalSentinel Free Tools Bot/1.0; +https://www.vitalsentinel.com/bot)
What this bot does, and how to block it

Stop checking by hand

Uptime, Core Web Vitals, indexing and robots.txt, monitored continuously. Start on the free plan and add your first domain in under a minute.

Free planNo credit cardCancel anytime