Checks

Domain is on the HSTS preload list

Chromium's public HSTS preload list already includes this domain.

Why it matters

Browsers that ship that list use HTTPS on the first visit, before they ever see the header.

What to do

Keep HTTPS, includeSubDomains, and a one-year max-age. Removing them can get the domain dropped from the list.

Reference

The Chromium HSTS preload list makes HTTPS the default before the first visit.

HSTS Preload