🔒 EXCLUSIVE: Web//https://hstspreload.appspot.com - HD Photos!

The Wayback Machine - https://web.archive.org/web/20150207011608/http://hstspreload.appspot.com:80/

Domain to include in HSTS list:

This form is used to submit domains for inclusion in Chrome's HTTP Strict Transport Security (HSTS) preload list. This is a list of sites that are hardcoded into Chrome as being HTTPS only. Firefox and Safari also have HSTS preload lists which include the Chrome list.

In order to be included on the HSTS preload list, your site must:

  1. Have a valid certificate.
  2. Redirect all HTTP traffic to HTTPS - i.e. be HTTPS only.
  3. Serve all subdomains over HTTPS.
  4. Serve an HSTS header on base domain:
    • Expiry must be at least eighteen weeks (10886400 seconds).
    • The includeSubdomains token must be specified.
    • The preload token must be specified.
    • If you are serving a redirect, that redirect must have the HSTS header, not the page it redirects to.

For more details on HSTS, please see RFC 6797. Note that the preload flag in the HSTS header is required to confirm and authenticate your submission to the preload list. An example valid HSTS header:

Strict-Transport-Security: max-age=10886400; includeSubDomains; preload

Submissions to the preload list are not automatic nor assured. All submissions undergo a manual review that may take one to several weeks. You can check the status of your request by entering the domain name again in the form above, or consult the current Chrome preload list by visiting chrome://net-internals/#hsts in your browser. Note that new entries are submitted to the Chrome source code and can take several months before they reach the stable version.

If you think you warrant special consideration, email Adam at agl at chromium dot org.