SEO-31
Missing HSTS (Strict-Transport-Security)
What the check measures
In the response headers of the home page we look for Strict-. If it is missing, the finding is raised. Only presence is judged: the contents of the header (max-age, includeSubDomains, preload) are not checked.
That is not an oversight: judging whether max-age is long enough would mean grading the quality of your security policy, and this group of checks deliberately does not. It only says the header is absent altogether.
Only the home page is checked, and only on a fresh crawl. When the audit runs over previously stored HTML the headers are unavailable and the check stays quiet: it does not report the header as missing. That is deliberate: claiming “missing” where we did not look would be untrue.
The finding attaches to the home page; severity is warning.
How strong the evidence is
We recommend it because it does no harm or has some other benefit, but we promise nothing about whether it makes language models cite you. Nobody has demonstrated that yet.
For visibility in AI answers and for ranking we have no documented effect and claim none. Google does not list security headers among its ranking signals; on the contrary, it writes explicitly that page experience aspects beyond Core Web Vitals do not directly help a site rank higher.
What HSTS does is documented and specific: it tells a browser to go straight to https on this domain next time and never try http. That closes the gap the redirect alone (SEO-30) leaves open: that one first insecure request, which can be intercepted and redirected elsewhere.
It is therefore a security measure, not an SEO measure, and it is in this manual because it appears next to SEO findings in the report and could be read that way. Do not read it that way.
When to skip it happily: when the site is still moving to HTTPS and you are not certain everything under the domain works (including subdomains, if you use includeSubDomains). HSTS enabled prematurely is worse than none; see the warning below.
How to fix it
The header belongs on https responses, not on http (there a browser ignores it):
Strict-Transport-Security: max-age=31536000; includeSubDomainsAnd now the warning, because of all the paid-module codes this is the one where a hasty fix can do the most damage.
- A browser remembers HSTS for the whole
max-age: a year at the value above. If yourhttpsstops working, visitors cannot reach the site at all, and removing the header will not undo it; they already remember. includeSubDomainsapplies to every subdomain, including the ones you forgot: internal tools, an old staging environment, a supplier's subdomain. All of them must speakhttps.- Roll it out gradually: start with
max-age=300(five minutes), confirm everything is fine, then raise it. - Add
preloadlast of all, knowing that removal from the browsers' list takes months.
The order is therefore: working certificate → http → https redirect (SEO-30) → short HSTS → long HSTS. Skipping a step risks an outage you cannot take back.
What the report says about it
Finding description
The homepage does not send a `Strict-
Recommendation
Add the `Strict-
Sources
- MDN: Strict-Transport-Security (accessed 2026-09-12)
- Google Search Central: Understanding page experience (accessed 2026-09-12)
Text verified 2026-09-12