dotvitals

The chain moves between hostnames

InfoConfirmedhttp.redirects.cross-host-hop

What this check looks for

Visitors are handed from one hostname to another along the way. That is normal — it is how www redirects and content networks work — and it is recorded here so the rest of the report makes sense.

Why it matters

Nothing is wrong. It is worth knowing because the security headers, cookies and certificate this report grades belong to the final host, not the one you typed, and because HSTS applies per host — a chain that leaves a hostname before it sends its HSTS header never protects that hostname.

What it costs your score

This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.

Severity
info
Default confidence
confirmed
Status when triggered
info
Deduction
0 points
Family cap
none
Category
HTTP
Module
Http redirects
Fix owned by
user
In the ruleset since
2026.09

How the whole score is calculated

Technical detail

‹detail›

Two consequences are worth checking. First, an HSTS header on the final host does not cover the host the visitor started at, so the first hop should send its own. Second, cookies set before the hop are not sent to the new host unless their Domain covers it.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the http redirects checker

Other http redirects checks