app Domain: The HTTPS Rule
Every .app domain is on the browser HSTS preload list, meaning browsers refuse to load any .app site over plain HTTP. You must have a valid SSL/TLS certificate installed before your site will display. Google Registry, which operates the .app TLD, built this requirement in at launch as a permanent security baseline.
Best fit once the com is gone
Β· Β· fit
Second choice
Β· Β· fit
Read this before you buy
First choice
Second choice
Zone type
Worst fit here
The whole shortlist, ranked on your answers
Fit is relative to the best-scoring extension for the four answers you gave β it is a ranking, not a rating out of a hundred. Change one answer and the order moves, which is the honest way to read any tool like this.
What HSTS Preload Means in Practice
HSTS β HTTP Strict Transport Security β is a mechanism that tells browsers to only connect to a domain over encrypted HTTPS. Most websites opt into HSTS by sending a response header, but .app and .dev take a different approach: they are included in the HSTS preload list that ships with every major browser. The browser enforces HTTPS before it ever contacts your server.
For site owners, this means two things. First, you need a valid SSL/TLS certificate from day one. Free certificates from Letβs Encrypt work perfectly β there is no requirement to purchase an expensive extended-validation certificate. Second, your hosting environment must support HTTPS. Most modern hosting platforms handle this automatically, but if you use a custom server configuration, you must set up the certificate yourself before pointing your .app domain to it. Without a certificate, visitors see a browser security warning instead of your site β not a fallback to HTTP, but an outright block.
Who Benefits and Who Should Think Twice
The enforced HTTPS requirement is an advantage for progressive web apps, which require a secure context to use features like service workers, push notifications and the Web App Manifest. If you are building a PWA, a .app domain guarantees the security baseline without relying on server configuration alone.
It also appeals to developers who want security by default and do not want to worry about mixed-content warnings or accidentally serving pages over HTTP during staging. The .dev extension from the same registry carries the identical HSTS preload requirement and targets a similar audience.
The extension is a poor fit if your hosting setup cannot easily support HTTPS β legacy shared hosting environments, some internal network tools or IoT dashboards served over local IP addresses. In those cases, .com imposes no TLD-level transport requirement. Use the TLD chooser to compare .app against .dev and .com based on your hosting setup, target audience and renewal budget β the HTTPS factor is one input among several that determine the right pick.
The HSTS preload requirement applies equally to .app and .dev. Both are operated by Google Registry under the same security policy.
Next in this cluster
Related domain guides
Sources
-
Google Registry .app and .dev documentation; HSTS preload list (hstspreload.org); Letβs Encrypt certificate authority documentation
- HSTS preload list β the
devandappzones are preloaded, so browsers refuse plain HTTP on them: hstspreload.org. - A generic top-level domain is not a ranking factor: Ahrefs glossary; Semrush.
- Practitioner reports on extension reputation, pricing and typo loss, quoted with the thread they came from: Hacker News 23799061, 41163433, 41729526.
- Counterweight on extension reputation β behaviour, not the extension, drives deliverability: Spamhaus.
- Country-code exposure precedent: CircleID on the vb.ly seizure.