Chrome HSTS Preload Checker

Audit your domain's HSTS configuration against Google Chrome, Firefox, and Safari preload inclusion standards to eliminate SSL stripping vulnerabilities.

What is HSTS Preloading?

HTTP Strict Transport Security (HSTS) tells browsers that a domain should ONLY be reached over HTTPS. However, on a user's very first visit, an attacker on the same network could intercept the initial HTTP request and strip the redirect. To eliminate this risk, Google maintains the HSTS Preload List—a hardcoded roster compiled directly into Chrome, Edge, Safari, and Firefox that forces HTTPS even before the first network connection is made.

Submitting to the Official Registry

Once all criteria pass, submit your domain at hstspreload.org to be included in major browser releases.