Audit your domain's HSTS configuration against Google Chrome, Firefox, and Safari preload inclusion standards to eliminate SSL stripping vulnerabilities.
HTTP Strict Transport Security (HSTS) tells browsers that a domain should ONLY be reached over HTTPS. However, on a user's very first visit, an attacker on the same network could intercept the initial HTTP request and strip the redirect. To eliminate this risk, Google maintains the HSTS Preload List—a hardcoded roster compiled directly into Chrome, Edge, Safari, and Firefox that forces HTTPS even before the first network connection is made.
Once all criteria pass, submit your domain at hstspreload.org to be included in major browser releases.