HTTP Strict Transport Security (HSTS) is a security feature that instructs web browsers to connect to your website using HTTPS only. Once enabled, visitors’ browsers will automatically use encrypted connections and reject insecure HTTP connections.
Before enabling HSTS, make sure your website is already accessible via HTTPS and that your SSL certificate is working correctly.
Table of Contents
Step 1: Log in to Cloudflare
Log in to your Cloudflare account and select the website you want to configure.
Step 2: Open SSL/TLS Settings
From the left-hand menu, navigate to:
SSL/TLS → Edge Certificates
Step 3: Enable HSTS
Scroll down to the HTTP Strict Transport Security (HSTS) section and click Enable HSTS.
Cloudflare will display a warning explaining the implications of enabling HSTS.
Step 4: Configure HSTS Settings
You can configure the following options:
Max Age
This determines how long browsers should remember the HSTS policy.
For initial testing, a shorter period such as:
1 month
is recommended.
After confirming everything works correctly, you can increase the duration.
Include Subdomains
Enable this option if all subdomains also support HTTPS.
Only enable it if every subdomain is accessible securely.
Preload
The preload option allows your domain to be included in browser HSTS preload lists.
Enable this option only if:
- HTTPS is permanently enabled on the entire domain.
- All subdomains support HTTPS.
- You understand that removing a preloaded domain can take months.
Step 5: Save the Configuration
Click Save to apply the changes.
Your website will now instruct browsers to use HTTPS connections exclusively.
Important Notes
- Ensure HTTPS is working correctly before enabling HSTS.
- Do not enable Include Subdomains unless all subdomains support HTTPS.
- Be cautious when enabling Preload, as it can be difficult to reverse.
- Test your website thoroughly after enabling HSTS to ensure there are no mixed-content or certificate-related issues.
Summary
HSTS is an additional security layer that helps protect visitors against downgrade attacks and accidental HTTP connections. When configured correctly in Cloudflare, it improves the security of your website by ensuring browsers always use HTTPS.