Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
ShieldCache 3 min read

Optimisation: HTTP/2, HTTP/3, compression, HSTS and security headers

In the Optimisation tab you determine how content reaches your visitors' browsers. Changes take effect with Apply.

Protocols

  • HTTP/1.1 for older programs and tools - always available.
  • HTTP/2 transfers several files simultaneously over one connection. It is used by all current browsers and is permanently switched on for all sites.
  • Offer HTTP/3 with QUIC (on by default): the latest protocol over UDP with faster connection setup and stable on changing networks, for example on mobile. ShieldCache announces it to browsers, which then switch over themselves.

Only switch off HTTP/3 if visitors behind firewalls have problems with UDP. ShieldCache then no longer announces it; browsers that already know HTTP/3 for your domain can still use it for up to 30 days. Encryption uses TLS 1.2 and 1.3 - always active.

Optimisation tab with HTTP/1.1, HTTP/2, HTTP/3, compression and HSTS
Optimisation tab: protocols at the top, compression and HSTS below.

Compression

The default is off: responses arrive as your server delivers them - most servers already compress them themselves. When switched on, ShieldCache compresses responses of 512 bytes or more with Zstandard or gzip if the browser supports it and the response is not yet compressed.

Compression and secret form values

If your website outputs secret values, such as form tokens, together with visitor input, compression over HTTPS can make attacks such as BREACH easier. In that case, leave compression off unless your server compresses anyway.

HSTS

With HSTS, browsers only connect to your domain via HTTPS. The default is “As the security headers”: the templates Standard, Static content and With HTTPS upgrade set HSTS for one year with subdomains and preload, while the “None” template sets no HSTS. Separately from this, you choose here:

  • Off: ShieldCache does not set HSTS. With the “None” template, an HSTS header from your server is retained.
  • On: HTTPS only for one year for this domain, without subdomains.
  • On with subdomains and preload: HTTPS only for one year for the domain and all subdomains, suitable for the browsers' preload list.

Be careful with preload

With preload, browsers require HTTPS for all subdomains - including those that do not run via ShieldCache. Choose “On” if a subdomain still needs to be reachable without HTTPS.

Security headers and file protection

In the Settings tab, General sub-tab, choose a template for the security headers under Redirect and security:

  • Standard: HSTS, protection against clickjacking and MIME sniffing, restricted browser permissions. Right for most websites.
  • Static content: like Standard, but without embedding protection and with sharing enabled for other websites - for images, scripts and fonts that other sites include.
  • With HTTPS upgrade: like Standard, plus a Content Security Policy that automatically loads insecurely included http content via HTTPS (mixed content).
  • None: ShieldCache does not set any headers of its own, and those from your origin remain.

The selected template replaces headers of the same name from your server. You set up custom headers and your own Content Security Policy in addition - see Content Security Policy and custom headers.

In the same area you will find the www redirect (none, to www or without www - both domains must be added) and file protection. File protection blocks access to sensitive files such as configuration, backups and version control - with profiles for WordPress, WooCommerce, Shopware, Joomla, Laravel and other applications. Blocked requests receive the error page SC-403-DATEI.

Redirect and security with www redirect, file protection and security headers
Redirect and security: www redirect, file protection profiles and the security header templates.

Was this article helpful?

New to SpeedIT Solutions?

Hosting where you know someone.

What you are reading here is what we put into practice for our customers every day. Based in Isernhagen since 2009 - with dedicated contact persons rather than a call centre.

  • 100% hosted in Germany
  • GDPR-compliant
  • Dedicated contact person
  • Provisioning within 24 hours
4.9 88 reviews on Expeero

Top webhoster

Auf der Suche nach einem webhoster mit guten Leistungen und moderaten Preisen bin ich auf SpeedIT gestoßen. Von der ersten Minute an bin ich sehr zufrieden und kann nur sagen: einfach top webhoster!
Aziz I.Recommends us · 08/06/2026

100 % recommend us · Expeero

All reviews on HOSTtest (opens in a new window)

You might also be interested in:

Personal support

Of course, our support team is also happy to assist you personally. If you cannot find what you are looking for in our knowledge base or require personalised support, please do not hesitate to contact us. We’re here to help you and to ensure that your experience with our products and services is as smooth and enjoyable as possible.