HTTPS-Only Mode tries to upgrade a website connection from HTTP to encrypted HTTPS. If the site cannot provide HTTPS, Firefox warns before allowing the insecure version. A router's local management page or old internal device may be a deliberate exception, but a financial or account login should not be casually opened over HTTP. Diagnose the destination and use a temporary, exact-site exception only when the risk is understood.
Before you start
Read the full domain or local IP address. Do not assume a padlock-shaped icon or familiar logo proves the page belongs to a real service. Avoid entering a password on an HTTP page over public Wi-Fi. For a router, use your own local network and its official manual.Do it step by step
- Check whether the site has an HTTPS address by navigating independently to its known official URL. A typo or redirected phishing page can produce an HTTP warning too.
- If it is a device page, confirm the address against its manual or label and verify you are on your own network. Try the manufacturer's documented HTTPS address or firmware update before allowing HTTP.
- In Firefox Settings, Privacy & Security, inspect HTTPS-Only Mode. For a necessary site, use Manage Exceptions or the site information panel and enter the exact address. Prefer a temporary exception for a one-time maintenance task.
- Reload and observe whether the address begins with http://. If it does, treat the connection as unencrypted. Do not submit reusable credentials, payment details or personal documents unless there is no safer supported path and you fully control the network.
- Complete the limited local task, then remove the temporary exception or verify its expiry. Recheck whether the device can enable HTTPS or receive an update.
- If the warning is for a public account site, stop. Contact the provider through an independently verified channel instead of making an exception to reach a sign-in page.