The host row names the site that can receive the rule.
The request names secure.example
The Host header is the site that can receive the HSTS rule.
Host=secure.example
The path is the root path
This toy request only needs the host and one small path.
path=/
The request body is empty
The blank line ends the headers in this pinned GET request.
request rows checked
Summary
The HSTS rule belongs to the exact host in the request row.
host checked