HSTS for Cloudflare Pages Functions

HTTP Strict Transport Security sounds boring right up until you need it. HSTS is the header that tells browsers: “stop trying plain HTTP for this site, always use HTTPS.” That shuts down protocol downgrade attacks and removes a whole class of accidental insecure requests. If your site is on Cloudflare Pages, adding HSTS is easy. Adding it safely is the part people mess up. I’ve seen teams copy-paste max-age=31536000; includeSubDomains; preload into production without checking whether every subdomain actually supports HTTPS. That’s how you brick old marketing hosts and weird internal tools. ...

September 3, 2026 · 6 min · headertest.com

HSTS Across Dev, Staging, and Prod: Common Mistakes

HSTS looks simple until you have more than one environment. On paper, it’s one header: Strict-Transport-Security: max-age=31536000; includeSubDomains In real teams, that header touches local development, preview deployments, staging subdomains, internal tools, CDNs, load balancers, and production rollback plans. That’s where people get burned. I’ve seen teams enable HSTS in production, break staging, lock developers out of test hosts, and then discover they can’t “just turn it off” because browsers cached the policy exactly like they were supposed to. ...

July 5, 2026 · 7 min · headertest.com

HSTS on Cloudflare Pages: Common Mistakes and Fixes

HSTS on Cloudflare Pages looks easy right up until it isn’t. You add a Strict-Transport-Security header, verify it in the browser, and move on. Then a week later you realize preview URLs behave differently, your apex domain redirects through a weird chain, or someone turned on preload without thinking about subdomains that still speak plain HTTP. I’ve seen this pattern a lot: HSTS gets treated like a checkbox. It’s not. On Cloudflare Pages, it’s simple to enable, but easy to misconfigure in ways that are annoying at best and production-breaking at worst. ...

June 15, 2026 · 7 min · headertest.com

How to enable HSTS in Cloudflare

If you’re using Cloudflare in front of your site, turning on HSTS is one of those small changes that can meaningfully tighten security with almost no ongoing maintenance. But it’s also one of those settings that’s easy to misunderstand, and if you flip it on carelessly, you can absolutely lock yourself into HTTPS behavior before your site is fully ready. So let’s do this the practical way: what HSTS actually does, what Cloudflare changes, the safe rollout path, and exactly where to click. ...

April 4, 2026 · 9 min · headertest.com