Domain is on the HSTS preload list
Chromium's public HSTS preload list already includes this domain.
Why it matters
Browsers that ship that list use HTTPS on the first visit, before they ever see the header.
What to do
Keep HTTPS, includeSubDomains, and a one-year max-age. Removing them can get the domain dropped from the list.
Reference
The Chromium HSTS preload list makes HTTPS the default before the first visit.