Cloudflare
Security & compliance
Releases
HSTS missing, disabled, or max-age under 6 months
Part of the Edge TLS posture check · fix arrives as a guide
What it is
HSTS is missing, disabled, or set with a max-age under six months.
Why it matters
Without HSTS the browser will try HTTP first on a fresh visit, which is the window an on-path attacker uses. A short max-age shrinks the protection to the point where most returning visitors have already forgotten it.
How to fix it
Enable HSTS with a max-age of at least six months, and include subdomains once you have confirmed every one of them serves HTTPS. Add preload only when you are certain — leaving the list takes months.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.