The chain moves between hostnames
What this check looks for
Visitors are handed from one hostname to another along the way. That is normal — it is how www redirects and content networks work — and it is recorded here so the rest of the report makes sense.
Why it matters
Nothing is wrong. It is worth knowing because the security headers, cookies and certificate this report grades belong to the final host, not the one you typed, and because HSTS applies per host — a chain that leaves a hostname before it sends its HSTS header never protects that hostname.
What it costs your score
This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.
- Severity
- info
- Default confidence
- confirmed
- Status when triggered
- info
- Deduction
- 0 points
- Family cap
- none
- Category
- HTTP
- Module
- Http redirects
- Fix owned by
- user
- In the ruleset since
- 2026.09
Technical detail
‹detail›
Two consequences are worth checking. First, an HSTS header on the final host does not cover the host the visitor started at, so the first hop should send its own. Second, cookies set before the hop are not sent to the new host unless their Domain covers it.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.