Firefox’s HTTPS-Only Mode helps protect your browsing by preferring encrypted connections whenever possible.
If you want to know how to enable HTTPS only mode in Firefox, this guide explains the exact steps, what the feature does, and when you may need to adjust it.
What HTTPS-Only Mode Does in Firefox
HTTPS-Only Mode tells Mozilla Firefox to use HTTPS instead of unencrypted HTTP whenever a site supports secure transport.
When you visit a page, the browser automatically upgrades the request to an encrypted connection so data is less exposed to interception or tampering.
This matters because HTTP traffic can reveal page content, login details, and session information to networks that should not see them.
HTTPS uses TLS encryption, which adds confidentiality and integrity for the connection between your browser and the website.
- HTTP: unencrypted web traffic
- HTTPS: encrypted web traffic using TLS
- HTTPS-Only Mode: Firefox tries HTTPS first and warns you if only HTTP is available
How to Enable HTTPS Only Mode in Firefox?
Enabling the feature is straightforward in Firefox on Windows, macOS, Linux, and mobile devices that support the setting.
The exact wording may vary slightly by version, but the path is consistent.
On desktop Firefox
- Open Firefox.
- Click the menu button in the top-right corner.
- Select Settings or Preferences.
- Open Privacy & Security.
- Scroll to the HTTPS-Only Mode section.
- Select Enable HTTPS-Only Mode in all windows.
Once enabled, Firefox will attempt secure connections across all browsing windows.
If a site does not support HTTPS, Firefox may show a warning page with an option to continue at your own risk.
On Firefox for Android
- Open the Firefox app.
- Tap the menu icon.
- Go to Settings.
- Find HTTPS-Only Mode under privacy-related options.
- Turn the feature on if available in your build.
Firefox for iOS has different platform limitations, so availability may differ depending on the app version and operating system policies.
Why Enabling HTTPS-Only Mode Improves Security
Modern browsers and websites increasingly use HTTPS by default, but not every site is configured correctly.
HTTPS-Only Mode provides an additional layer of browser-level enforcement that reduces accidental exposure to insecure endpoints.
Security benefits include:
- Encrypted traffic that is harder to read on public Wi-Fi
- Reduced downgrade risk when a site has both HTTP and HTTPS variants
- Fewer mixed-scheme visits that can weaken browser trust
- Cleaner browsing habits by pushing the web toward secure defaults
This is especially useful if you often use coffee shop Wi-Fi, airport networks, hotel networks, or unmanaged home routers.
On these networks, plain HTTP traffic is easier to intercept than TLS-protected traffic.
What Happens When a Site Does Not Support HTTPS?
If Firefox cannot find a secure version of a website, it will usually display a security warning instead of loading the page silently over HTTP.
That behavior is intentional, because it prevents you from unknowingly sending data through an unencrypted connection.
You may still be able to click through the warning for non-sensitive pages, such as legacy informational sites.
However, you should avoid entering passwords, payment details, or personal information if a site lacks HTTPS.
Common reasons a site fails in HTTPS-Only Mode include:
- The site has no valid TLS certificate
- The site’s HTTPS configuration is broken
- Redirects are misconfigured
- Older internal systems still rely on HTTP
How to Allow Exceptions in Firefox
Sometimes you may need to access a trusted internal tool or a legacy website that still depends on HTTP.
Firefox lets you create exceptions so you can keep HTTPS-Only Mode on while permitting specific sites.
- Open the site that triggers the HTTPS warning.
- Review the warning carefully.
- If you trust the site, choose the option to continue to the HTTP version.
- Firefox may remember the exception depending on your settings and version.
Use exceptions sparingly.
Every exception weakens the protection provided by HTTPS-Only Mode, so it is best to limit them to sites you understand and trust.
How HTTPS-Only Mode Works with Other Firefox Privacy Features
Firefox includes several privacy tools that complement HTTPS-Only Mode.
Together, they can significantly reduce tracking and exposure to insecure web behavior.
- Enhanced Tracking Protection: helps block cross-site trackers
- DNS over HTTPS: encrypts DNS lookups in supported configurations
- Strict cookie controls: limit third-party tracking cookies
- Site Isolation: helps reduce cross-site data leakage in memory
These features solve different problems.
HTTPS-Only Mode protects the connection to the website, while tracker blocking and cookie controls reduce how sites observe and profile your activity.
When You Might Want to Turn It Off
Although HTTPS-Only Mode is generally recommended, there are cases where administrators or power users may disable it temporarily.
This can be useful when debugging a site, testing a development environment, or using a legacy intranet that has not been migrated to HTTPS.
Possible reasons to disable it include:
- Testing a local development server on HTTP
- Accessing outdated internal applications
- Verifying redirect behavior for a migration project
- Troubleshooting certificates or proxy issues
If you do disable the feature, re-enable it as soon as you finish the task.
For everyday browsing, the security benefit usually outweighs the inconvenience.
Troubleshooting HTTPS-Only Mode Problems
If a secure site is not loading correctly, the issue may not be HTTPS-Only Mode itself.
A broken certificate chain, expired certificate, corporate proxy, or content filter can also prevent secure connections.
Check the website address
Make sure the URL is typed correctly.
Many sites support HTTPS only on a specific domain or subdomain, and a typo can send you to a domain that does not.
Inspect the certificate warning
If Firefox shows a certificate error, review whether the problem is the site, your local network, or a managed device policy.
Corporate environments often install trusted root certificates for interception or inspection.
Update Firefox
Keep Mozilla Firefox updated so you benefit from the latest TLS support, security fixes, and browser policy changes.
Older versions may behave differently or support fewer modern cipher suites.
Test another network
If a site works on mobile data but fails on public Wi-Fi, the network may be intercepting or blocking encrypted traffic.
That can point to firewall rules, captive portals, or filtering devices.
Best Practices for Using HTTPS-Only Mode
To get the most out of Firefox’s security controls, combine the setting with practical browsing habits.
The goal is not only to enable the feature, but also to reduce risk in everyday use.
- Keep Firefox up to date
- Use strong, unique passwords with a password manager
- Prefer websites that support modern TLS certificates
- Avoid bypassing warnings unless you trust the site
- Review browser settings after major updates
For organizations, it can also help to standardize browser policy through enterprise management tools so employees use consistent secure settings across devices.
Why This Setting Matters in 2026
In 2026, encrypted web traffic is no longer optional for most serious security workflows.
As phishing, session hijacking, and network-based interception continue to evolve, browser-level protections like HTTPS-Only Mode remain one of the simplest ways to harden everyday browsing.
If you are asking how to enable HTTPS only mode in Firefox, the short answer is that it takes only a few clicks.
The more important answer is that turning it on helps enforce a safer baseline for every site you visit, especially when you cannot control the network you are using.