SEO-31

Missing HSTS (Strict-Transport-Security)

WarningCrawler access

What the check measures

In the response headers of the home page we look for Strict-Transport-Security. If it is missing, the finding is raised. Only presence is judged: the contents of the header (max-age, includeSubDomains, preload) are not checked.

That is not an oversight: judging whether max-age is long enough would mean grading the quality of your security policy, and this group of checks deliberately does not. It only says the header is absent altogether.

Only the home page is checked, and only on a fresh crawl. When the audit runs over previously stored HTML the headers are unavailable and the check stays quiet: it does not report the header as missing. That is deliberate: claiming “missing” where we did not look would be untrue.

The finding attaches to the home page; severity is warning.

How strong the evidence is

Effect not demonstrated

We recommend it because it does no harm or has some other benefit, but we promise nothing about whether it makes language models cite you. Nobody has demonstrated that yet.

For visibility in AI answers and for ranking we have no documented effect and claim none. Google does not list security headers among its ranking signals; on the contrary, it writes explicitly that page experience aspects beyond Core Web Vitals do not directly help a site rank higher.

What HSTS does is documented and specific: it tells a browser to go straight to https on this domain next time and never try http. That closes the gap the redirect alone (SEO-30) leaves open: that one first insecure request, which can be intercepted and redirected elsewhere.

It is therefore a security measure, not an SEO measure, and it is in this manual because it appears next to SEO findings in the report and could be read that way. Do not read it that way.

When to skip it happily: when the site is still moving to HTTPS and you are not certain everything under the domain works (including subdomains, if you use includeSubDomains). HSTS enabled prematurely is worse than none; see the warning below.

How to fix it

The header belongs on https responses, not on http (there a browser ignores it):

Strict-Transport-Security: max-age=31536000; includeSubDomains

And now the warning, because of all the paid-module codes this is the one where a hasty fix can do the most damage.

  • A browser remembers HSTS for the whole max-age: a year at the value above. If your https stops working, visitors cannot reach the site at all, and removing the header will not undo it; they already remember.
  • includeSubDomains applies to every subdomain, including the ones you forgot: internal tools, an old staging environment, a supplier's subdomain. All of them must speak https.
  • Roll it out gradually: start with max-age=300 (five minutes), confirm everything is fine, then raise it.
  • Add preload last of all, knowing that removal from the browsers' list takes months.

The order is therefore: working certificate → http → https redirect (SEO-30) → short HSTS → long HSTS. Skipping a step risks an outage you cannot take back.

What the report says about it

Finding description

The homepage does not send a `Strict-Transport-Security` header. Without it, the browser does not force `https://` when the domain is typed directly, leaving the first visit vulnerable to a downgrade attack. This is a standard security recommendation, not an SEO trick; we have no evidence it affects visibility in AI assistant answers.

Recommendation

Add the `Strict-Transport-Security: max-age=31536000; includeSubDomains` header at the server/CDN level, once the `https://` redirect (SEO-30) is working and stable.

Sources

Text verified 2026-09-12