dotvitals

The site is not set up for HSTS preloading

InfoConfirmedweb.security-headers.hsts-not-preloaded

What this check looks for

Browsers only learn to force HTTPS after the first visit. Preloading builds that instruction into the browser itself, so even the very first visit is secure.

Why it matters

Nothing is wrong here — preloading is optional and deliberately hard to undo. It is offered because it closes the one gap HSTS cannot: the very first request a browser ever makes to your site.

When the check passes, your report says: “The site is preloaded, so even a first visit is secure”.

What it costs your score

This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.

Severity
info
Default confidence
confirmed
Status when triggered
info
Deduction
0 points
Family cap
none
Category
Web security
Module
Web security headers
Fix owned by
user
In the ruleset since
2026.09

How the whole score is calculated

Technical detail

‹detail›

The preload list requires max-age of at least ‹required max age›, includeSubDomains, preload, and a redirect from HTTP to HTTPS on the same host. Removal takes months and browsers ship the list in their binaries, so treat submission as a decision rather than a setting.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the web security headers checker

Other web security headers checks