Security Lock
Hannah Maitland

HTTP Strict Transport Security

20th Dec 2021 SEO Blog 2 minutes to read

Koozai > Blog > HTTP Strict Transport Security


HTTP Strict Transport Security

HSTS or Strict Transport Security is a standard defined in RFC 6797, by which a web server can declare to a client that it should only be accessed via HTTPS. The web server or crawler will then make all future requests over HTTPS. This will be the case even if following a link to an HTTP URL. From here the SEO Spider shows a Status Code of 307 and a Status of HSTS Policy and a Redirect Type of HSTS Policy.

This redirect is an internal representation in the SEO Spider and the browser. This differs from a 301 or a 302 as it isn’t sent by the web server as its turned around internally. When a webserver declares it should be contacted through HTTPS an expiry on this – this 307 response is ideal as it means temporary re-direct.

Protocol

The HSTS protocol is based on the server sending a single header. This is called a Strict-Transport-Security and is only sent via HTTPS as if sent via HTTP it is overlooked. The header requires 2 associated directives max-age and includeSubDomains.

Max-age is mandatory and lets the server know the number of seconds in which it can only be contacted by HTTPS. IncludeSubDomains is an optional field which if set, signals that HSTS Policy applies to any sub-domains.

Benefits

There are several benefits to using HTTP – > HTTPS Redirect. It reduces the communication over non-secure protocols, reduces load on the web server as well as improving the performance as a round trip is avoided when the HTTP link is encountered.

A site-wide HTTP->HTTPS redirect is still needed due to the Strict-Transport-Security header ignoring this unless it is sent over the HTTPS. If the first visit to your site is not via HTTPS, you still need that initial redirect to HTTPS to deliver the Strict-Transport-Security header. Considering this, you may not expect to see a 307 in the SEO Spider, but makes an HTTP request for the robots.txt file, receives a 301 to the HTTPS version of the site, then receives the Strict-Transport-Security header, so will then report 307 for the first URL crawled. If robots.txt is disabled checking the SEO spider will report a 301.

How to disable HSTS

This can be easily done by unticking: ‘Respect HSTS Policy’ configuration under ‘Configuration > Spider > Advanced’ in the SEO Spider.

The SEO Spider will ignore HSTS completely and report upon the underlying redirects and status codes.

Share this post

Hannah Pennington

Client Services Manager

With over a decade of experience in marketing, digital strategy and sales, Hannah is a talented all-rounder marketer. Having worked with big-name brands including Bandai, Toni & Guy, the BBC and DMG, Hannah’s experience translates to being an exceptional client services manager. Spending her spare time creating something artistic or volunteering for a local charity, she’s a valuable member of the Koozai team.

What do you think?

aspect-ratio
Gary Hainsworth

What is Black Hat SEO?

Gary Hainsworth
22nd Sep 2023
SEO Blog
aspect-ratio
Gary Hainsworth

The Importance of Keywords in SEO

Gary Hainsworth
19th Sep 2023
SEO Blog

Digital Ideas Monthly

Sign up now and get our free monthly email. It’s filled with our favourite pieces of the news from the industry, SEO, PPC, Social Media and more. And, don’t forget - it’s free, so why haven’t you signed up already?

We create cutting edge, award-winning digital marketing campaigns

Digital Marketing Audits

Are you a UK business that needs some expert help to uncover what’s holding your digital marketing back? Let us show you!

Questions?

Call us on 0330 353 0300, email info@koozai.com or fill out our Contact Form.

Map of Hampshire Digital Marketing Agency
Hampshire Digital Marketing Agency
Merlin House 4 Meteor Way Lee-on-the-Solent, PO13 9FU, UK
Map of Lancashire Digital Marketing Agency
Lancashire Digital Marketing Agency
Cotton Court Business Centre Church Street, Preston Lancashire, PR1 3BY, UK
Map of London Digital Marketing Agency
London Digital Marketing Agency
Albert House 256 - 260 Old Street London, EC1V 9DD, UK

Unlike 08 numbers, 03 numbers cost the same to call as geographic landline numbers (starting 01 and 02), even from a mobile phone. They are also normally included in your inclusive call minutes. Please note we may record some calls.

Circle Cross