Cloudflare Security & compliance Releases

HSTS missing, disabled, or max-age under 6 months

Part of the Edge TLS posture check · fix arrives as a guide

What it is

HSTS is missing, disabled, or set with a max-age under six months.

Why it matters

Without HSTS the browser will try HTTP first on a fresh visit, which is the window an on-path attacker uses. A short max-age shrinks the protection to the point where most returning visitors have already forgotten it.

How to fix it

Enable HSTS with a max-age of at least six months, and include subdomains once you have confirmed every one of them serves HTTPS. Add preload only when you are certain — leaving the list takes months.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.