Trusted Web Hosting | SECURE_INFRA: CAN_NODE_01 | ENCRYPTION: AES-256-GCM | Documentation |
Security & SSL

What Is HSTS and Why You Should Enable It

Published on Mar 20, 2026 Updated on Jul 31, 2026 1 views

Even with SSL installed, there's a brief window where a visitor's first request to your site could occur over unencrypted HTTP — HSTS closes that gap.

The Vulnerability It Fixes

Without HSTS, an attacker on the same network could intercept that first unencrypted request before the redirect to HTTPS happens, a technique known as SSL stripping.

How HSTS Works

Once a browser has visited your HTTPS site once, HSTS tells it to always connect via HTTPS from then on, automatically, without ever attempting an unencrypted connection again.

Enabling It

HSTS is enabled through a response header, configurable in Plesk or your server configuration — confirm your SSL setup is stable before enabling it, since it's not instantly reversible for returning visitors.

Further Reading


Back to Knowledgebase: Knowledgebase
Was this helpful?