Skip to content

Unsure about HSTS preload: submit or not, and how do I get out again?

HSTS preload pins your domain into the hardcoded list of Chrome, Firefox, Safari, Edge. No browser will ever do HTTP for your domain again. Strong for security, but exiting can take months. Only submit after everything is 100 percent HTTPS, including all subdomains.

Try this first

  1. 1Prerequisites: all subdomains on HTTPS, server sends HSTS header with max-age 31536000 (1 year) plus includeSubDomains plus preload.
  2. 2Test at hstspreload.org whether you qualify. If the check fails, fix it first, submit after.
  3. 3Submit at hstspreload.org. It takes weeks to months until it ships in browser releases.
  4. 4Realize that removal via the removal procedure takes the same months. A misconfigured subdomain stuck on HTTP locks that domain out for customers.
  5. 5For SMB: a server-side HSTS header is usually enough, preload is for those who want 100 percent browser certainty.

When to bring us in

If you want to submit preload and want to be sure all paths are ready, we can run a pre-check that flags red flags before submission.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.