You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于example.com的HSTS状态疑问:Chrome显示已启用但无响应头?

Why Chrome Shows Dynamic HSTS Rules for example.com (No STS Header in Responses)

Great question—this is a common point of confusion with how Chrome handles HSTS. Let’s break down what’s happening here:

1. The Dynamic HSTS Record Lives in Your Local Chrome Instance, Not on the Server

The dynamic_* prefix in the chrome://net-internals/#hsts output tells you this rule is stored locally in your browser, not pulled from the site’s HTTP headers or Chrome’s global HSTS preload list. There are a few common ways this could have happened:

  • Manual addition: Someone using this Chrome profile might have visited chrome://net-internals/#hsts before, used the "Add domain" feature to manually set example.com to force HTTPS and include subdomains. This creates a local rule that persists until you delete it or it expires (if you set an expiration time when adding).
  • Previous STS header from the site: At some point in the past, example.com might have sent a valid Strict-Transport-Security header. Chrome stores that rule locally for the duration specified in the max-age parameter. Even if the server stops sending the header later, Chrome will keep enforcing the rule until the max-age expires.
  • Third-party extensions or tools: Some security-focused browser extensions or system-level tools can automatically add HSTS rules for domains to enforce HTTPS, even without the server sending the header.

2. Does the Site Actually Have HSTS Enabled?

No, not currently. HSTS is a server-side feature—for a site to be "officially" using HSTS, it must send the Strict-Transport-Security HTTP header in its HTTPS responses. The rule you’re seeing is just Chrome’s local enforcement, which isn’t tied to the server’s current configuration.

To confirm this, you can:

  • Use browser dev tools (Network tab) to inspect the response headers from https://example.com—if there’s no Strict-Transport-Security present, the server isn’t serving it right now.
  • Delete the dynamic rule from chrome://net-internals/#hsts (use the "Delete domain" option), then refresh the site and re-check the HSTS status. If the rule doesn’t reappear, that confirms the server isn’t sending the header.

内容的提问来源于stack exchange,提问作者Anatoli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 10:00:31