Hsts on google.com

Is really Google.com on HSTS ?

Google announced bringing  HTTP Strict Transport Security (abbreviated as HSTS) to www.google.com. HSTS is a web security policy mechanism which allows a web server to enforce the use of HTTPS in a compliant User Agent (UA), such as a web browser. It lets a website tell web browsers that it should only be communicated with using HTTPS instead of using HTTP.

Although Google moved on HTTPS long before many well-known top sites such as Twitter, Facebook or Wikipedia, it is the last bringing HSTS to google.com among them. Besides, as announced on Google Blog, HSTS is brought for the moment only to www.google.com.

Below are Google's as well as some top sites dates of HTTPS migration.

Google      18/10/2011

Twitter       13/02/2012

Facebook  01/08/2013

Wikipedia  12/06/2015

Soon after Google's HSTS announcement, Youtube followed the same path and shared bringing HSTS to Youtube.

Youtube HSTS

A website server needs to return Strict-Transport-Security HTTP header in order to enable HSTS when the site is accessed over HTTPS. However no Strict-Transport-Security HTTP Header is returned from www.google.com when HTTP header of www.google.com is fetched although this header is returned from other top sites which are cited above.

A second way of checking this information is through Chrome.The Google Chrome browser offers a quick way to check a domain's HSTS status via chrome://net-internals/#hsts. Querying domain www.google.com on chrome://net-internals/#hsts gives the result below.

chrome hsts google.com

STRICT  as dynamic_upgrade_mode means that the browser has been instructed to enable HSTS by an HTTP response header.

Third way of verifying the information given by google about bringing HSTS to google.com is checking Chrome's HSTS preload list which is a list of sites that are hardcoded into Chrome as being HTTPS only. Most major browsers (Chrome, Firefox, Opera, Safari, IE 11 and Edge) also have HSTS preload lists based on the Chrome list.

A sample from this list is below.

Thanks for taking time to read this post. I offer consulting, architecture and hands-on development services in web/digital to clients in Europe & North America. If you'd like to discuss how my offerings can help your business please contact me via LinkedIn

Have comments, questions or feedback about this article? Please do share them with us here.

If you like this article

Follow Me on Twitter

Follow Searchdatalogy on Twitter

Related Tags: HTTPS  


About Us

My objective is bringing all my experience and expertise together to deliver solid technology solutions that can take your search traffic acquisition to the next level. My main goal is to assist you in building and maintaining your search marketing analytics platforms. My will is to leverage your marketing and IT teams search knowledge while bridging the gap between two.


Botify: Botify Certified Consultant

IBM: Data Scientist, Data Engineering Certificates

Google: Google Analytics, Google Adwords, Mobile Sites, Digital Sales Certificated Professional

Coursera: Data Engineering on Google Cloud Platform Specialization

Legal Terms Privacy

Recent Posts

SEO data distribution analysis 6 months, 4 weeks ago
87 million domains pagerank 1 year, 4 months ago
SEO data forecasting 1 year, 5 months ago
SEO data analysis 1 year, 5 months ago
BrightonSEO conference 1 year, 6 months ago
HTTP2 on top sites 1 year, 9 months ago
Desktop & mobile performances 2 years, 1 month ago
Alexa top 1 million sites 2 years, 1 month ago
Best SEO conferences in 2019 2 years, 2 months ago
Web marketing festival 2 years, 9 months ago
Webcampday 2 years, 10 months ago
Queduweb 2 years, 11 months ago
1 million #SEO tweets 3 years, 1 month ago
SEO, six blind men & an elephant 3 years, 2 months ago
SEO hero 2017 3 years, 3 months ago
Digitalzone 3 years, 4 months ago
Technical SEO log analysis 3 years, 4 months ago

Recent Tweets