SCANTIDE ONLINE
Scantide Online Guide

How to Check HTTPS and HSTS from the Outside

External testing shows what a public user actually receives: whether HTTP redirects to HTTPS, whether certificates validate, and whether the HTTPS response publishes HSTS.

Technical guideUpdated 25 September 2026Scantide Online
Short answer: External testing shows what a public user actually receives: whether HTTP redirects to HTTPS, whether certificates validate, and whether the HTTPS response publishes HSTS.

Test the public path, not just the server config

Load balancers, CDNs and reverse proxies can change redirects and response headers after the origin server configuration.

HTTP and HTTPS should be reviewed together

A secure HTTPS endpoint does not automatically mean the HTTP entry point behaves as expected.

HSTS is visible in the HTTPS response

The browser-facing header reveals whether the public service tells compatible browsers to prefer HTTPS in the future.

Online provides an outside-in check

Scantide Online can review HTTP/HTTPS reachability, TLS and security headers from the public side so teams can compare the delivered result with intended configuration.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.

Current Scantide source: Public Server Security Assessment

Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.

Current Scantide source: Website Security Header Scanner

Scantide Online reviews website security headers such as HSTS, CSP, X-Frame-Options and related browser controls in the context of the public site.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.

Field experience from the archive

Historical source · JufCorp: Using HTTP redirects for mitigating vulnerability scans and bruteforce attacks

As a test, I changed all of the .php-files to simply redirect to https://www.google.com and then triggered a response by using an invalid username (I have mine set to immediately block if someone tries to use an invalid username) and, behold., it worked. Next time I tried to browse to /wp-admin I got redirected to Google for as long as the rule says so.

The redirect method will only protect your server on the http/s level. f you also have other services runnning such as FTP,RDP etc they won't be protected by a simple redirect on http/s only. There's other ways to accoomplish that and I'm happy to help you out. Just drop me an email or get in contact through the form to the right or below.

Historical source · JufCorp: Anyone ideas? How to disable vompatibility check in Excel 2007?

Disbling compatibiliy check when opening 2003 .xls in @Office 2007 impossible. Gah. Comp-check f##%s it up in remote app when alt pg up don't work.

Historical source · JufCorp: Syspeace first public month - 40 000+ brute force attacks blocked!

So far,our first public month.40 000+ brute force attacks successfully blocked and traced! #rdp #windowsserver #infosec http://t.co/KOlgoMLO -- Syspeace (@Syspeace)

Historical source · JufCorp: Securing your servers, users and customers online

Also, you external DNS server needs to be secured! Have a word with your ISP or whoever is running the external DNS server and see what they've got in place.

Remember to check your mail queues on a regular basis If you're starting to have loads of undelivered mail to and from various domains you could actually have a DNS server that's under attack , not being able to service your Exchange server with required information .

Practical review checklist

Frequently asked questions

Can an internal configuration check replace an external one?

No. The public path may include intermediaries that change the result.

Does HSTS work on the first-ever HTTP visit?

Not by itself unless preload or prior browser state is involved; the browser needs to know the policy.

Check the evidence with Scantide Online

External domain security, privacy and infrastructure assessment. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Run Scantide OnlineMore guidesAll Scantide guides