HSTS (HTTP Strict Transport Security) is a security header that forces browsers to always use an encrypted HTTPS connection to your website, even if a visitor accidentally clicks an http link. This prevents downgrade attacks and man-in-the-middle attacks. You set up HSTS via a header on your web server or in Plesk, and with just a few lines of configuration your site is immediately better protected.
What is HSTS and why do you need it
Without HSTS, a browser can still connect to your site via an unencrypted http connection on the first visit, before being redirected to https. That moment is vulnerable: an attacker can intercept that initial connection and redirect the user to a fake page. HSTS solves this by telling the browser: remember that this site can only be reached via HTTPS, for a certain period. On every subsequent visit, the browser automatically skips the unencrypted step.
This is especially important for websites with login forms, payment details, or other sensitive information. For a business website too, it’s a simple way to increase the trust of visitors and search engines.
Setting up HSTS via Plesk or server configuration
When using Plesk, you can often enable HSTS directly via the web hosting or SSL/TLS certificate settings, without editing configuration files yourself. If you run your own server with LiteSpeed or Apache, you add the header manually.
Check your SSL certificate
Make sure your domain has a valid SSL certificate and that HTTPS works correctly before enabling HSTS.
Add the HSTS header
Add the header in your server configuration or .htaccess: Strict-Transport-Security with a validity period, for example one year.
Test your configuration
Use an online header checker to verify that the HSTS header is actually sent with an https request.
Increase the validity period
Start with a shorter period and gradually increase it once you’re sure everything is working properly.
In Plesk, you’ll find the SSL/TLS settings for the relevant domain under the Hosting tab. If you’re unsure about the correct setting, Tandata’s 24/7 support is happy to help via WhatsApp, ticket, or email.
HSTS preload and subdomains
By default, HSTS only applies from the first visit to your site onward. For even better protection, you can register your domain with the HSTS preload list, which is built into browsers. This way, the browser already knows before the first visit that your site only works via HTTPS.
Note: once your domain is on the preload list, this applies to all subdomains. Make sure every subdomain, including any subdomains for email or other services, is also accessible via HTTPS before setting this up. If you use subdomains for business email, also check your email hosting settings.
Avoiding common mistakes
A common mistake is enabling HSTS while not all parts of the site are already running on HTTPS, which can cause visitors to lose access to certain pages or subdomains. Therefore, first check all parts of your site, including images, scripts, and subdomains.
Another pitfall is setting a long validity period right away. Browsers remember the setting for the specified period, so if something goes wrong, you can’t quickly undo it. Build up the setting step by step.
If you manage multiple domain names, make sure you check each domain individually to confirm that HTTPS works correctly before setting up HSTS. Switching to a hosting provider that handles SSL and security properly by default can significantly simplify this process.
More background information on security and server settings can be found in Tandata’s knowledge base.
Frequently Asked Questions
Does HSTS work without an SSL certificate?
No, HSTS only works in combination with a valid SSL certificate, because the header is sent via an https connection.
Can I turn HSTS off again?
Yes, but browsers that have already remembered the header will continue to enforce HTTPS until the set validity period has expired.
Is HSTS mandatory for every website?
No, it’s not mandatory, but it is strongly recommended for websites with forms, logins, or sensitive data.
Does HSTS affect the speed of my website?
No, HSTS has no noticeable impact on load time; in fact, it saves a redirect step on subsequent visits.
Does HSTS also apply to my email environment?
HSTS applies specifically to web traffic via the browser. Different settings apply to email security β see your business email settings.
Conclusion
HSTS is a simple but effective way to run your website entirely on HTTPS and prevent downgrade attacks. With a valid SSL certificate, the right header, and a gradual build-up of the validity period, you secure your site reliably.