{"id":8366,"date":"2023-01-09T01:00:39","date_gmt":"2023-01-08T17:00:39","guid":{"rendered":"https:\/\/www.cldy.com\/support\/?post_type=docs&#038;p=8366"},"modified":"2023-01-09T14:40:11","modified_gmt":"2023-01-09T06:40:11","password":"","slug":"what-is-hsts-force-hsts-website-security","status":"publish","type":"docs","link":"https:\/\/www.cldy.com\/support\/help\/what-is-hsts-force-hsts-website-security\/","title":{"rendered":"What is HSTS and How To Force HSTS for Website Security"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">If a website visitor comes to your site and sees &#8220;Not secure&#8221;, they are more likely to leave and close the page right away. Security is one of those things that are highly important to all users, and should always be a priority when developing your website. That is why forcing HSTS (HTTP Strict Transport Security) is a great practice to always ensure a secure connection. How do you do it? Read on to learn our simple steps.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">But first, let&#8217;s get acquainted with what HSTS is and how it works.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><b>What is HSTS<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Aside from validating your SSL certificates, forcing HSTS is another way to ensure that your website will always be deemed secure by Google Chrome and other browsers.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In order to force HSTS, you must have the following:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A valid SSL certificate from a trusted authority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A .htaccess file that contains a specific header for HSTS configuration<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">We will dive into the second point, which is adding an HSTS header on your .htaccess file.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>How to Force HSTS for Increase Website Security<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">1. Log in to your cPanel dashboard.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">2. Go to the <\/span><b>Files <\/b><span style=\"font-weight: 400;\">block, and click on <\/span><b>File Manager<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-large wp-image-8368\" src=\"https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-dashboard-files-file-manager-1024x141.png\" alt=\"cpanel dashboard files - file manager\" width=\"800\" height=\"110\" srcset=\"https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-dashboard-files-file-manager-1024x141.png 1024w, https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-dashboard-files-file-manager-300x41.png 300w, https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-dashboard-files-file-manager-768x106.png 768w, https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-dashboard-files-file-manager.png 1161w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">3. The <\/span><i><span style=\"font-weight: 400;\">.htaccess<\/span><\/i><span style=\"font-weight: 400;\"> file may be under hidden files, so make sure to go to <\/span><b>Settings<\/b><span style=\"font-weight: 400;\"> at the top right corner of the screen, and tick the box for <\/span><b>Show Hidden Files (dotfiles)<\/b><span style=\"font-weight: 400;\">. Then click on <\/span><b>Save<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-large wp-image-8369\" src=\"https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-file-manager-settings-show-hidden-files-1024x539.png\" alt=\"cpanel file manager settings show hidden files\" width=\"800\" height=\"421\" srcset=\"https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-file-manager-settings-show-hidden-files-1024x539.png 1024w, https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-file-manager-settings-show-hidden-files-300x158.png 300w, https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-file-manager-settings-show-hidden-files-768x405.png 768w, https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/cpanel-file-manager-settings-show-hidden-files.png 1236w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">4. You will notice there will be additional folders visible on your screen. Look for the <\/span><i><span style=\"font-weight: 400;\">.htaccess<\/span><\/i><span style=\"font-weight: 400;\"> file and right-click, then select <\/span><b>Edit<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-8371\" src=\"https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/htaccess-file-right-click-edit.png\" alt=\"htaccess file right click edit\" width=\"415\" height=\"276\" srcset=\"https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/htaccess-file-right-click-edit.png 415w, https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/htaccess-file-right-click-edit-300x200.png 300w\" sizes=\"(max-width: 415px) 100vw, 415px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">5. A dialog box will appear to confirm that you will be making changes to the <\/span><i><span style=\"font-weight: 400;\">.htaccess<\/span><\/i><span style=\"font-weight: 400;\"> file. Click on <\/span><b>Edit<\/b><span style=\"font-weight: 400;\"> to continue.<\/span><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-8370\" src=\"https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/htaccess-file-confirm-edit.png\" alt=\"htaccess file confirm edit\" width=\"502\" height=\"346\" srcset=\"https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/htaccess-file-confirm-edit.png 502w, https:\/\/www.cldy.com\/support\/wp-content\/uploads\/sites\/12\/2023\/01\/htaccess-file-confirm-edit-300x207.png 300w\" sizes=\"(max-width: 502px) 100vw, 502px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">6. The file will then open on a new window. Simply copy this line and paste to the header of the text:<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400; font-family: 'Courier New';\">Header set Strict-Transport-Security &#8220;max-age=10886400; includeSubDomains; preload&#8221;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">7. Click on <\/span><b>Save Changes<\/b><span style=\"font-weight: 400;\">, then <\/span><b>Close<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">8. To confirm if the HSTS header has been enforced correctly, go to <\/span><a href=\"https:\/\/hstspreload.org\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">https:\/\/hstspreload.org\/<\/span><\/a><span style=\"font-weight: 400;\">. Enter your domain and click on <\/span><b>Check HSTS preload status and eligibility<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">The page will turn red or green based on the results. Look into the corresponding improvements that are needed to make sure that the HSTS header is detected properly.\u00a0<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If a website visitor comes to your site and sees &#8220;Not secure&#8221;, they are more likely to leave and close the page right away. Security is one of those things that are highly important to all users, and should always be a priority when developing your website. That is why forcing HSTS (HTTP Strict Transport [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"footnotes":""},"doc_category":[47,31],"doc_tag":[],"class_list":["post-8366","docs","type-docs","status-publish","hentry","doc_category-cpanel","doc_category-web-hosting"],"year_month":"2026-07","word_count":367,"total_views":0,"reactions":{"happy":0,"normal":0,"sad":0},"author_info":{"name":"syd123","author_nicename":"syd123","author_url":"https:\/\/www.cldy.com\/support\/author\/syd123\/"},"doc_category_info":[{"term_name":"cPanel","term_url":"https:\/\/www.cldy.com\/support\/help-category\/cpanel\/"},{"term_name":"Web Hosting","term_url":"https:\/\/www.cldy.com\/support\/help-category\/web-hosting\/"}],"doc_tag_info":[],"_links":{"self":[{"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/docs\/8366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/comments?post=8366"}],"version-history":[{"count":4,"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/docs\/8366\/revisions"}],"predecessor-version":[{"id":8375,"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/docs\/8366\/revisions\/8375"}],"wp:attachment":[{"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/media?parent=8366"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/doc_category?post=8366"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.cldy.com\/support\/wp-json\/wp\/v2\/doc_tag?post=8366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}