Strict-Transport-Security: max-age=31536000; includeSubDomains
is a promise to the browser that all future requests to this domain will be secure.
For the future time period max-age
HSTS behavior is meant to eliminate Man-in-the-Middle attacks that use HTTPS stripping, issuing of invalid certificates (and expecting the user to add and exception), and redirecting on HTTP requests to another destination.