How to force HTTPS and enable HSTS on a site
HTTPS redirect and HSTS are on by default; change them per site, and understand why HSTS is only sent where a valid certificate exists.
The redirect from HTTP to HTTPS and the HSTS header come on by default; your plan sets the default and you can change it for each site.
Steps
- Open Websites, site, Options.
- Check HTTP to HTTPS redirect and HSTS and set them as you want.
- Save and test with
curl -I http://example.com(you should see a redirect) andcurl -I https://example.com(you should seeStrict-Transport-Security).
Why HSTS is conditional
Once a browser has seen HSTS it refuses plain HTTP for that domain for the whole period. If the certificate were missing or expired the site would be unreachable and could not be fixed from the server. So the panel sends HSTS only on sites with a valid certificate.
Other fixed options on the same page
Redirects, error pages, index listing, upload size, hotlink protection, IP blocking and password-protected directories (hashed with SHA-512 and stored outside your web root). The same options apply in Apache, nginx and OpenLiteSpeed.
Last updated: 2026-10-10