How to force HTTPS (redirect HTTP to HTTPS)

Send every visitor to the secure version of your site with an .htaccess rule or WordPress settings, without creating a redirect loop.

How-to guideBeginner2 min readUpdated

Once your certificate is installed, redirect all traffic to https://.

Important: Check https://yourdomain.co.uk loads without a warning before forcing HTTPS. Forcing it without a working certificate sends every visitor to an error.

Any website: .htaccess

  1. Open System Info & Files then File Manager and go to your domain’s public_html.
  2. Show hidden files if .htaccess isn’t visible. How to show hidden files like .htaccess
  3. Edit .htaccess (create it if it doesn’t exist) and add at the top:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
  1. Save, then visit http://yourdomain.co.uk in a private window. It should change to https://.

WordPress

  1. Go to Settings → General.
  2. Change both WordPress Address and Site Address to begin https://.
  3. Save. You’ll be logged out and asked to log in again over HTTPS.

WordPress then redirects most pages itself. Adding the .htaccess rule above as well covers every file, including images linked from old URLs. Put it above the # BEGIN WordPress block.

Don’t redirect twice in conflicting ways

Choose one place to handle www/non-www and HTTPS. A plugin forcing HTTPS, an .htaccess rule and a Cloudflare setting that all redirect differently can loop. “Too many redirects” and HTTPS redirect loops

Going further: HSTS

HSTS tells browsers to use HTTPS automatically on future visits:

Header always set Strict-Transport-Security "max-age=31536000"

Only add it once HTTPS works everywhere on the domain, including subdomains you use.

Popular

Tip: press / to search from any pageSee all results