Skip to content
Nemo edited this page Oct 29, 2019 · 1 revision

TWA-0204

Message

"Strict-Transport-Security, but no preload"

Explanation

Setting a preload directive marks the STS header as being eligible for the HSTS Preload list, which is used by all major browsers. Note that setting the preload directive by itself doesn't add your website to the list, you must be eligible as per the criteria and make a submission on the website.

Remediation

In your webserver, set the preload directive on the Strict-Transport-Security header.

Clone this wiki locally