FYI, this is happening because of HSTS. Basically, if you hit pioneer2.net without a subdomain, you will end up requesting https://pioneer2.net which returns the following header:
strict-transport-security: max-age=31536000; includeSubDomains
This header instructs the browser not to trust http...