Enable HSTS in Cloudflare for Stronger SSL Security Updated on May 27, 2021 by InMotion Hosting Contributor 1 Minutes, 33 Seconds to Read Whether you’re using shared or VPS hosting services to create a website, it’s important to have a SSL certificate for added security. But it is not enough to install a domain validated SSL. You need to ensure your web server only serves website requests with an encrypted connection. This is accomplished with a 301 redirect in your .htaccess file. For additional security you can use HTTP Strict Transport Security (HSTS) which forces browsers to request HTTPS pages from your domain. This is typically configured within your .htaccess file. However, those using the Cloudflare content delivery network (CDN) for improved website speed can enable this with a few clicks. Below we’ll cover how to enable HSTS using Cloudflare. Enable HSTS in Cloudflare Log into Cloudflare.On the top, select Crypto.Select Enable HSTS.Read the acknowledgement to ensure you fully understand the implications of enabling HSTS. The most important thing to understand is that you must have an active SSL certificate installed for the domain at all times. Otherwise, your website will become inaccessible from your web browser until the HTTP header expires. Select Next.Select the toggle button for Enable HSTS (Strict-Transport-Security).Set the Max Age Header (max-age) which determines how long the security HTTP header should be active.Toggle Apply HSTS policy to subdomains (includeSubDomains) if desired. Do not select this if you have subdomains that aren’t publicly facing and don’t have an SSL.Select Preload if you’d like to submit your website to HSTSpreload.org for preload listing if eligible.You can enable No-Sniff Header. However, you should configure Content Security Policy (CSP) in your .htaccess file which controls what the browser can load within your website in superior ways.After you configure your preferences, press Save at the bottom. Learn more within Cloudflare documentation. Learn how to maximize your Linux systems with our Cloud Server Product Guide. If you don’t need cPanel, don't pay for it. Only pay for what you need with our scalable Cloud VPS Hosting. CentOS, Debian, or Ubuntu No Bloatware SSH and Root Access Share this Article InMotion Hosting Contributor Content Writer InMotion Hosting contributors are highly knowledgeable individuals who create relevant content on new trends and troubleshooting techniques to help you achieve your online goals! More Articles by InMotion Hosting Related Articles How to Fix the “550 No Such User Here” Email Error What is Node.js? How to Deploy Websites Generated by AI Builders on Your Server How to Use robots.txt Disallow to Block Crawlers and Protect Site Performance Content Security Policy (CSP) Headers – Complete Reference Guide Troubleshooting SSL Connection Errors: How to Fix HTTPS Issues How to Check and Repair a Database in phpMyAdmin 21 Reasons Your Website is Slow and How to Speed it Up Website Transfer Resources Ensure a Successful Website Transfer