Back to report
Strict-Transport-Security header
SEOWeight 1.0% (This check's share of the SEO score)Score 100
What this is
Whether the server tells browsers to always use the encrypted connection for this site from now on (HSTS).
Why it matters
This is mainly a security setting that prevents connections from being tampered with on the way. Its direct effect on ranking is very small, but it's a basic safeguard.
What counts as passing
Passes when the server response includes a Strict-Transport-Security setting; fails when it doesn't.
Evidence
| Current HSTS setting | max-age=63072000 |
|---|
Raw data
Check ID seo.https.hsts
{
"header": "max-age=63072000"
}Suggestion
Pro plan onlyAdd Strict-Transport-Security header
Set an HSTS header to enforce HTTPS in browsers.
Before / After
Current
(none)
Suggested
Strict-Transport-Security: max-age=31536000; includeSubDomains