HSTS Preload List Submission

HSTS Preload List Submission

To maximize protection, submit your domain to browser preload lists:

Prerequisites for preload:

  1. Valid certificate on base domain and all subdomains
  2. Redirect HTTP to HTTPS on same host
  3. All subdomains must serve over HTTPS
  4. HSTS header with max-age >= 31536000
  5. Must include includeSubDomains directive
  6. Must include preload directive

Submission process:

# Verify HSTS configuration
curl -I https://example.com | grep -i strict-transport

# Test with SSL Labs
# https://www.ssllabs.com/ssltest/

# Submit to preload list
# https://hstspreload.org/