I wonder why no (proper) https?
But that's not something that even client-side code supplied by HTTP should be capable of ensuring, considering that somebody could have intercepted it somewhere on the route and replaced it with something that does send it somewhere.
Depending on how you host, the easiest solution might be to use the caddy web server which has letsencrypt built in.