Enabling HSTS without proper planning and communication, especially with marketing teams, can lead to various problems. A central issue is that HSTS enforces HTTPS connections, and if existing HTTP links in emails, websites, and marketing materials aren't updated to HTTPS, users experience broken links and a degraded experience. This impacts SEO, reduces traffic, conversions, and breaks client campaigns if ESPs are incompatible. SSL mismatch errors can occur if ESPs don't fully support SSL on their click-tracking endpoints. The lack of coordination between IT and marketing results in reactive problem-solving rather than proactive planning. Ensuring a fully functional HTTPS setup and aligning all systems to support HTTPS is essential for a smooth transition.
9 marketer opinions
Enabling HSTS (HTTP Strict Transport Security) without proper planning and communication, particularly with marketing teams, can lead to significant problems. HSTS enforces HTTPS connections, and if existing HTTP links in emails, websites, and other marketing materials aren't updated to HTTPS, users will encounter broken links and a degraded experience. This can negatively impact SEO, reduce traffic and conversions, and break client campaigns if ESPs are not compatible. Coordination between IT and marketing is essential to ensure a smooth transition and avoid disruptions.
Marketer view
Email marketer from Cloudflare explains enabling HSTS without ensuring that all links and resources resolve over HTTPS can negatively impact SEO. Broken links lead to a poor user experience and may harm search engine rankings. Marketing must be involved to ensure a smooth transition.
2 May 2022 - Cloudflare
Marketer view
Email marketer from Stack Overflow responds that if a website enables HSTS and does not update all internal links to HTTPS, the website will break. The marketing team may see an immediate reduction in traffic and conversions.
13 Oct 2022 - Stack Overflow
3 expert opinions
Enabling HSTS without thorough preparation can lead to broken links and SSL mismatch errors, negatively impacting the user experience. A core issue arises when HSTS is activated without first ensuring all assets, especially those in older email campaigns, are served over HTTPS. Furthermore, if an ESP's click-tracking endpoints don't universally support SSL, users may encounter SSL mismatch errors upon clicking email links. Therefore, it's crucial to verify that all systems are HTTPS-compatible and that HSTS is implemented carefully to avoid these disruptions.
Expert view
Expert from Email Geeks explains that if an ESP's click tracking endpoints support SSL but don't have it enabled for all customers, enabling HSTS for a domain can result in users encountering SSL mismatch errors when clicking email links, leading to a poor user experience. Some ESPs need to upgrade their systems to ensure HTTPS support is standard for all customers.
21 Nov 2022 - Email Geeks
Expert view
Expert from Email Geeks explains the problem is people turning HSTS on without ensuring it doesn't break anything.
6 May 2025 - Email Geeks
4 technical articles
Enabling HSTS without proper planning results in accessibility and configuration errors, primarily due to broken links. HSTS enforces HTTPS connections, automatically upgrading HTTP requests to HTTPS. If existing HTTP links in emails and websites aren't updated, users will encounter failed connections and errors, leading to broken user journeys. A fully functional HTTPS setup is a prerequisite, and coordination across teams, particularly with marketing, is essential to ensure all internal and third-party links are updated before HSTS deployment. Incorrect configuration or premature deployment without these considerations leads to accessibility issues.
Technical article
Documentation from Mozilla Developer Network explains that HSTS instructs browsers to only connect to a website over HTTPS. If a user types `http://example.com`, the browser automatically upgrades the connection to `https://example.com`. Without proper planning, existing `http://` links in emails will fail, leading to broken user journeys.
9 Apr 2022 - Mozilla Developer Network
Technical article
Documentation from OWASP explains that while HSTS improves security, incorrect configuration or premature deployment can lead to accessibility issues. If internal or third-party links are not updated to HTTPS, users will encounter errors. Coordination with all teams, including marketing, is vital.
14 May 2024 - OWASP
Does domain/IP reputation affect BIMI logo display with VMC?
How can I improve email deliverability and open rates for a client with a bad domain reputation, especially with Gmail, and what strategies should I use for unengaged users?
How can I improve my domain health and avoid the Google domain dog house?
How can I prevent my sales team's email practices from negatively impacting my domain reputation?
How do DMARC, spam complaints, and IP reputation affect email deliverability and rejections?
How do subdomain deliverability issues affect parent domains, and what are the primary causes of email deliverability problems?