HSTS Preloading
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/hsts-preloading/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/hsts-preloading/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/hsts-preloading/)
Use the native HTML custom element.
HSTS (HTTP Strict Transport Security) Preloading ist der Prozess, eine Domain in die fest codierten Listen der Browserhersteller einzureichen, die vorschreiben, dass bestimmte Sites immer über HTTPS abgerufen werden müssen – noch vor dem ersten Besuch. Im Gegensatz zum Standard-HSTS-Header (der beim ersten Verbindungsaufbau gelernt wird) sind vorgeladene Domains bereits ab der allerersten Anfrage geschützt – auch bei völlig neuen Browserinstallationen. Zur Qualifikation für das Preloading muss eine Domain ein gültiges [[ssl-tls|TLS-Zertifikat]] bereitstellen, alle HTTP-Anfragen auf HTTPS umleiten, einen HSTS-Header mit max-age von mindestens 31536000 Sekunden setzen und die Direktiven preload und includeSubDomains einschließen. Einige gesamte [[tld|TLDs]] wie .dev und .app sind auf TLD-Ebene HSTS-vorgeladen.
Beispiel
After submitting stripe.com to the HSTS preload list, any browser — even one that has never visited Stripe — will refuse to connect over plain HTTP, preventing SSL stripping attacks.