Short answer
Add a redirect in your
.htaccess file that sends every http:// request to the https:// version. Do this only after the certificate is issued and working, otherwise visitors hit a security warning they cannot get past.Learn more
- How to force HTTPS (redirect HTTP to HTTPS)Send every visitor to the secure version of your site with an .htaccess rule or WordPress settings, without creating a redirect loop.
- How to fix mixed content warningsWhy a site on HTTPS still shows ‘not fully secure’, how to find the insecure images, scripts and styles, and how to fix them for good.
- Redirects with .htaccess: copy-ready examplesWorking .htaccess redirect rules for single pages, whole folders, domain changes, HTTPS and www — with notes on 301 vs 302 and avoiding loops.
Step-by-step
- Make your site secure with HTTPSBeginner · 15 min · 7 steps