How to force HTTPS and enable HSTS on a site

How-to Websites and PHP httpshstsredirectsite options

HTTPS redirect and HSTS are on by default; change them per site, and understand why HSTS is only sent where a valid certificate exists.

The redirect from HTTP to HTTPS and the HSTS header come on by default; your plan sets the default and you can change it for each site.

Steps

  1. Open Websites, site, Options.
  2. Check HTTP to HTTPS redirect and HSTS and set them as you want.
  3. Save and test with curl -I http://example.com (you should see a redirect) and curl -I https://example.com (you should see Strict-Transport-Security).

Why HSTS is conditional

Once a browser has seen HSTS it refuses plain HTTP for that domain for the whole period. If the certificate were missing or expired the site would be unreachable and could not be fixed from the server. So the panel sends HSTS only on sites with a valid certificate.

Other fixed options on the same page

Redirects, error pages, index listing, upload size, hotlink protection, IP blocking and password-protected directories (hashed with SHA-512 and stored outside your web root). The same options apply in Apache, nginx and OpenLiteSpeed.

Last updated: 2026-10-10