Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

What Is HSTS? A Simple Guide

HSTS tells browsers to always use the secure version of your site. This guide explains how it works and how to turn it on.

SSL and Security2 min read7 steps

What is HSTS?

HSTS stands for HTTP Strict Transport Security. It is a rule your website gives to the browser. The rule says: "Only talk to me over HTTPS." HTTPS is the secure, locked way of loading a website. It needs an SSL certificate, which is like an ID card for your site.

Why is it useful?

Even if you redirect http to https, the first visit can still start on the unlocked version. Someone on the same public Wi-Fi could trick the visitor in that moment. With HSTS, the browser remembers your rule. Next time, it goes straight to the secure version. It never uses the unlocked one.

Before you turn it on

  • Your SSL certificate must be valid and working on every page.
  • Your site should already open correctly with https.
  • Know that browsers remember the rule for a set time. If your certificate later breaks, visitors will see errors and cannot click past them.

Test first with a short time, then raise it.

Steps to enable HSTS on Apache

Apache is a common web server program. Many hosting accounts use it. Take a backup of your .htaccess file before you change it.

  1. Log in to cPanel and open File Manager.
  2. Go to your site's main folder, often public_html.
  3. If you cannot see .htaccess, click Settings and tick Show Hidden Files.
  4. Right-click .htaccess and choose Edit.
  5. Add these lines at the top:
<IfModule mod_headers.c>
Header always set Strict-Transport-Security "max-age=300"
</IfModule>

This tells browsers to remember the rule for 300 seconds, which is five minutes. It is a safe test.

  1. Click Save Changes and open your site to check it still loads.
  2. When all is fine, raise max-age. A common long value is 31536000, which is one year.

Check that it works

Open your site in a browser. Open the developer tools, look at the Network tab, click the page request and read the response headers. You should see Strict-Transport-Security.

Tip: Do not add the preload option until you are very sure. It is hard to undo.

Quick recap

  • HSTS forces browsers to use HTTPS for your site.
  • It needs a working SSL certificate first.
  • Add the header to .htaccess on Apache.
  • Start with a short time, then increase it.