Protected return visits
The browser goes straight to HTTPS instead of beginning a later visit over an insecure connection.
HSTS tells a browser to remember that the site must use HTTPS. On later visits, the browser avoids insecure HTTP and will not allow a dangerous certificate error to be bypassed.

The browser goes straight to HTTPS instead of beginning a later visit over an insecure connection.
Less risk of security warnings during sign-in, form completion or an order.
A single correct header replaces conflicting CDN, panel and server settings.
max-age and test the site.| Element | Status | Reason |
|---|---|---|
| HSTS for the main site | Included | The core deliverable. |
| Working SSL and HTTPS redirect | Before HSTS | Enabling the policy without them is unsafe. |
includeSubDomains | After review | Every subdomain must permanently support HTTPS. |
| HSTS Preload | Separate | A long-term commitment whose removal can take months. |
To investigate first, use the safe deployment guide or the manual HSTS check.
We need the domain, a subdomain inventory and, after approval, secure server, panel or CDN access. Preload and subdomain coverage are never enabled without separate confirmation.
Enter the domain below. We will check the current header and propose a safe configuration.