# Help adding includeSubDomains to the Strict-Transport-Security header

**URL:** https://meta.discourse.org/t/help-adding-includesubdomains-to-the-strict-transport-security-header/381983
**Category:** Self-hosting
**Tags:** hosting
**Created:** [September 8, 2025, 9:09pm UTC](https://meta.discourse.org/t/help-adding-includesubdomains-to-the-strict-transport-security-header/381983 "2025-09-08T21:09:38Z")
**Posts on this page:** 1
**Showing post:** 5

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [September 22, 2025, 2:16pm UTC](https://meta.discourse.org/t/help-adding-includesubdomains-to-the-strict-transport-security-header/381983/5 "2025-09-22T14:16:05Z")

</div>

> [@pfaffman](#):
>
> not setting `includeSubDomains` was a security issue

I would call it a configuration choice instead.

> [@pfaffman](#):
>
> whether having IncludeSubDomains in the the STS header was important

Is the forum on an apex domain or not?

I always tell people that we are very cautious of setting headers that affect other hostnames on their domain, and if they want to have HSTS on those, they should set the headers on those respective hosts instead.

The only valid reason I can think of is they cannot do that, e.g. when the forum is on an apex domain and the client is not able to control the HSTS headers on other externally hosted hosts, e.g. they have [hostedshopify.example.com](http://hostedshopify.example.com) as well. Then they basically come to you because you’re the path of least resistance 🙂

---

_[View the full topic](https://meta.discourse.org/t/help-adding-includesubdomains-to-the-strict-transport-security-header/381983)._
