HSTS Preload List Submission
HSTS Preload List Submission
To maximize protection, submit your domain to browser preload lists:
Prerequisites for preload:
- Valid certificate on base domain and all subdomains
- Redirect HTTP to HTTPS on same host
- All subdomains must serve over HTTPS
- HSTS header with max-age >= 31536000
- Must include includeSubDomains directive
- Must include preload directive
Submission process:
# Verify HSTS configuration
curl -I https://example.com | grep -i strict-transport
# Test with SSL Labs
# https://www.ssllabs.com/ssltest/
# Submit to preload list
# https://hstspreload.org/