AVAILABLE FOR WEB, FLUTTER & QA PROJECTS

How to use this tool

1. Enter Domain Name

Type your apex domain (e.g. example.com) to simulate the browser check.

2. Verify 5 Core Criteria

Check off valid SSL, HTTP-to-HTTPS redirect on port 80/443, and subdomain coverage.

3. Verify Max-Age Duration

Ensure max-age is set to at least 31,536,000 seconds (1 full year).

4. Review Submission Warnings

Review irreversible inclusion caveats before submitting to the official hstspreload.org registry.

Formula or logic used

Official Chromium HSTS Preload Requirements

Strict technical prerequisites mandated for hardcoded inclusion in Chrome, Firefox, and Safari browser binaries.

  • Rule 1: Serve a valid, trusted SSL/TLS certificate on the apex domain
  • Rule 2: Redirect all HTTP requests on port 80 to HTTPS on port 443 on the same host
  • Rule 3: Serve all subdomains over HTTPS (includeSubDomains is mandatory)
  • Rule 4: Set max-age to at least 31,536,000 seconds (1 year)
  • Rule 5: Include the explicit 'preload' directive token in the header

Examples

Example 1: Compliant Production Domain

Input: Domain: https://faisalrafique.com | Header: max-age=63072000; includeSubDomains; preload
Calculated Result: Result: 100% Preload Ready | All 5 Chromium Criteria Satisfied

Domain meets or exceeds all security guidelines for permanent browser vendor preloading.

Example 2: Disqualified Domain (Short max-age & Missing Subdomains)

Input: Domain: https://legacy-app.com | Header: max-age=86400
Calculated Result: Result: Fails (max-age too short; missing includeSubDomains; missing preload flag)

1-day max-age is insufficient; submitting without HTTPS subdomains risks taking internal services offline.

Common use cases

SSL Security Hardening Audits

Audit client web properties against SSL Labs A+ and Mozilla Observatory security standards.

Man-in-the-Middle (MITM) Prevention

Eliminate SSL-stripping attacks on the initial insecure HTTP request.

Enterprise Subdomain Governance

Verify that all internal microservice and API subdomains possess valid SSL certificates before enabling preload.

Web Agency Handover Validation

Deliver fully preloaded and encrypted domain architectures to corporate clients.

Web Developer Tools

CSP Header Generator

The CSP Header Generator builds customized Content-Security-Policy response headers that restrict executable s...

Launch Tool →
Web Developer Tools

Cache-Control Header Generator

The Cache-Control Header Generator creates standardized HTTP caching directives instructing browsers and CDN e...

Launch Tool →
Technical SEO Tools

Canonical Tag Checker

The Canonical Tag Checker inspects HTML head tags and URLs to detect duplicate canonical declarations, protoco...

Launch Tool →

Frequently asked questions

What is HSTS Preloading?

HSTS Preload is a program managed by the Google Chromium project where domain names are hardcoded directly into Chrome, Firefox, Safari, and Edge browser binaries. When preloaded, browsers will never attempt an insecure HTTP connection to the domain, even on the user's first visit.

What happens if an internal subdomain does not support HTTPS?

Because HSTS Preload enforces includeSubDomains globally, any subdomain (e.g., dev.example.com, intranet.example.com) that lacks a valid SSL certificate will become completely inaccessible to all users in all modern browsers.

Can an HSTS preloaded domain be removed from the list?

Removal from the HSTS Preload list is possible but extremely slow. It requires submitting an official removal request and waiting several months for browser vendors to deploy updated browser versions to all worldwide users.

What is the recommended testing phase before adding the preload directive?

Gradually step up max-age over several weeks: start with max-age=300 (5 minutes), then max-age=86400 (1 day), then max-age=2592000 (1 month) with includeSubDomains, before committing to 1 year + preload.

Blueprint Grid Background
AVAILABLE FOR NEW CONTRACTS & ARCHITECTURAL BUILDS

Let's build something
exceptional together

Work directly with Faisal Rafique to architect and deliver high-performance Next.js 15 platforms, 60fps Flutter mobile applications, and enterprise automated QA testing pipelines.

Direct Senior Architect Access
100% Code & IP Ownership
Milestone-Based Global Delivery