If your website has an active SSL certificate, you can automatically redirect visitors from HTTP to HTTPS using rules placed in the .htaccess file.
This ensures that all visitors access the secure version of your website, regardless of whether they enter:
http://yourdomain.com or
https://yourdomain.com Table of Contents
Before You Begin
Make sure that:
- An SSL certificate is active for your domain.
- HTTPS works correctly when accessed directly.
- The website uses Apache-compatible
.htaccessrules.
Redirect All Traffic to HTTPS
Open the .htaccess file located in your website’s main directory, typically:
public_html/.htaccess Add the following rules near the beginning of the file:
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] How It Works
RewriteEngine Onenables URL rewriting.RewriteCond %{HTTPS} !=onchecks whether the connection is not using HTTPS.RewriteRuleredirects the visitor to the HTTPS version of the same URL.R=301creates a permanent redirect, which is recommended for SEO purposes.
Redirect All Traffic to HTTPS and WWW
If you want all visitors to use both HTTPS and the www prefix, use the following rules instead:
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://www.%{HTTP_HOST}%{REQUEST_URI} [L,R=301] Example:
http://yourdomain.com becomes:
https://www.yourdomain.com Alternative: Redirect to HTTPS Without WWW
If you prefer the non-WWW version of your website, you can use:
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://yourdomain.com%{REQUEST_URI} [L,R=301] Replace:
yourdomain.com with your actual domain name.
Verify the Redirect
After saving the .htaccess file:
- Open your website using
http://. - Confirm that the browser automatically redirects to
https://. - Verify that the SSL certificate is displayed correctly and that no security warnings appear.
Common Issues
If the redirect does not work:
- Verify that the SSL certificate is active.
- Ensure the
.htaccessfile is located in the correct directory. - Check for conflicting redirect rules.
- Clear your browser cache before testing again.
If you encounter a redirect loop, review any existing HTTPS redirects configured within your CMS, plugin, or application settings.
Summary
To force all visitors to use HTTPS, add the following rule to your website’s .htaccess file:
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] This permanently redirects all HTTP requests to the secure HTTPS version of your website, helping improve security, user trust, and SEO performance.