Once your certificate is installed, redirect all traffic to https://.
Important: Check https://yourdomain.co.uk loads without a warning before forcing HTTPS. Forcing it without a working certificate sends every visitor to an error.
Any website: .htaccess
- Open System Info & Files then File Manager and go to your domain’s
public_html. - Show hidden files if
.htaccessisn’t visible. How to show hidden files like .htaccess - Edit
.htaccess(create it if it doesn’t exist) and add at the top:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
- Save, then visit
http://yourdomain.co.ukin a private window. It should change tohttps://.
WordPress
- Go to Settings → General.
- Change both WordPress Address and Site Address to begin
https://. - Save. You’ll be logged out and asked to log in again over HTTPS.
WordPress then redirects most pages itself. Adding the .htaccess rule above as well covers every file, including images linked from old URLs. Put it above the # BEGIN WordPress block.
Don’t redirect twice in conflicting ways
Choose one place to handle www/non-www and HTTPS. A plugin forcing HTTPS, an .htaccess rule and a Cloudflare setting that all redirect differently can loop. “Too many redirects” and HTTPS redirect loops
Going further: HSTS
HSTS tells browsers to use HTTPS automatically on future visits:
Header always set Strict-Transport-Security "max-age=31536000"
Only add it once HTTPS works everywhere on the domain, including subdomains you use.