-
Notifications
You must be signed in to change notification settings - Fork 96
Open
Description
Trying https://fowardemail.net there is a 302 redirect to https://forwardemail.net/<locale> (e.g. https://forwardemail.net/en) where hsts header is present
Strict-Transport-Security: max-age=31557600; includeSubDomains; preload
hstspreload.org responds with Error: No HSTS header Response error: No HSTS header is present on the response.
Does the missing hsts header on the initial response and 302 redirect to where hsts header is present cause the issue?
I can see http -> https redirect via 301.
wget -O- --no-hsts http://forwardemail.net:80
--2020-10-16 07:51:50-- http://forwardemail.net/
Resolving forwardemail.net (forwardemail.net)... 167.71.85.68
Connecting to forwardemail.net (forwardemail.net)|167.71.85.68|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: https://forwardemail.net/ [following]
--2020-10-16 07:52:00-- https://forwardemail.net/
Using competitors like https://gf.dev/hsts-test says things are good.
Metadata
Metadata
Assignees
Labels
No labels