HSTS header looks preload-ready
The header has preload, includeSubDomains, and a one-year max-age, but the public list does not show the domain as preloaded.
Why it matters
The directive alone does not put the domain on the list. Browsers only preload names that were submitted and accepted.
What to do
Submit the domain at hstspreload.org after every subdomain is confirmed on HTTPS.
Reference
The Chromium HSTS preload list makes HTTPS the default before the first visit.