chromium / hstspreload.org

:lock: Chromium's HSTS preload list submission website.
https://hstspreload.org
BSD 3-Clause "New" or "Revised" License
782 stars 92 forks source link

Preloading using DNS TXT #253

Closed juliaszone closed 10 months ago

juliaszone commented 10 months ago

Hi, I have some domains I want to preload, but the tool seems to require some HTTPS check and a header. I believe it would be nice to be able to submit a domain in a different way: a TXT record on the root domain, i.e. example.com IN TXT "hsts-preload". It would make it easier to have domains preloaded, but for example you host an IPv6 only website (which doesnt work with hsts-preload.org) or you don't want to host a webserver on the root of the domain, but still want it preloaded for example for future use or the subdomains.

nharper commented 10 months ago

The use case of not having a webserver on the root of the domain is not a valid reason for not meeting the requirements on hstspreload.org. There is a bug (#43) tracking hstspreload.org's inability to check IPv6-only domains.

The eligibility criteria listed on hstspreload.org for preloading a domain are intentionally chosen, and we have no plans to offer a way to preload a domain that doesn't meet the listed criteria. In cases where there are bugs with the automated system (e.g. its lack of IPv6 support), we will consider manually processing such domains. https://github.com/chromium/hstspreload.org/wiki/Preload-List-Processes#requirements-for-manual-hsts-entries