Complete step-by-step guide for mjsconnect.com
✅ You should now see the mjsconnect.com dashboard with tabs like "Analytics", "DNS", "SSL/TLS", etc.
📍 Location: SSL/TLS → Edge Certificates
✅ You should see options like "Always Use HTTPS", "Automatic HTTPS Rewrites", etc.
⚠️ Important: Read this warning before enabling
HSTS forces all connections to use HTTPS. Make sure your site works properly over HTTPS before enabling this.
Click "I understand" checkbox in the Cloudflare popup to proceed.
Status: Enabled
Max Age Header (max-age):
(This is 12 months in seconds)
Apply HSTS policy to subdomains (includeSubDomains):
Preload:
(Allows browsers to preload HSTS)
No-Sniff Header:
(Sends X-Content-Type-Options: nosniff)
✅ Part 1 Complete! HSTS is now enabled. Move to Part 2 to add the remaining security headers.
📍 Location: Rules → Transform Rules → Modify Response Header
💡 This means the security headers will be added to ALL pages on mjsconnect.com
Now we'll add 7 security headers. For each header, you'll click "+ Set static" and fill in the name and value.
✅ After adding this header, click "+ Set static" again to add the next one
✅ After adding this header, click "+ Set static" again to add the next one
✅ After adding this header, click "+ Set static" again to add the next one
✅ After adding this header, click "+ Set static" again to add the next one
✅ After adding this header, click "+ Set static" again to add the next one
✅ After adding this header, click "+ Set static" again to add the next one
✅ Part 2 Complete! All security headers are now configured.
Wait 2-3 minutes for Cloudflare's changes to propagate globally.
Use these tools to verify everything is working:
✅ You should see:
Need help? Contact your IT administrator or email humanresources@mjsia.com with screenshots of any errors.
🎉 Congratulations!
You've successfully configured industry-standard security headers for mjsconnect.com. Your employee data is now better protected against common web vulnerabilities.