{"id":277,"date":"2026-09-27T10:05:05","date_gmt":"2026-09-27T17:05:05","guid":{"rendered":"https:\/\/hostandtech.com\/kb\/?p=277"},"modified":"2026-09-27T10:05:05","modified_gmt":"2026-09-27T17:05:05","slug":"force-https-redirect-http-to-https","status":"publish","type":"post","link":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/","title":{"rendered":"How to Force HTTPS: Redirect HTTP to HTTPS in cPanel, Plesk, .htaccess, Nginx and IIS"},"content":{"rendered":"<h2>Overview<\/h2>\n<p>To redirect HTTP to HTTPS, turn on <strong>Force HTTPS Redirect<\/strong> in cPanel&#8217;s <strong>Domains<\/strong> page, or tick <strong>Permanent SEO-safe 301 redirect from HTTP to HTTPS<\/strong> in Plesk&#8217;s hosting settings. If you need more control, add a three-line rewrite rule to <code class=\"\" data-line=\"\">.htaccess<\/code>, a <code class=\"\" data-line=\"\">return 301<\/code> server block in Nginx, or a URL Rewrite rule in IIS. Whichever you pick, use <strong>one<\/strong> method only and make it a single 301 that also settles www versus non-www.<\/p>\n<p>This guide is for anyone who has an SSL certificate installed and still sees <code class=\"\" data-line=\"\">http:\/\/<\/code> versions of their pages load, in browsers or in Google Search Console. You&#8217;ll finish with every HTTP address sending a permanent redirect straight to the right HTTPS address, a test that proves it, and fixes for the redirect loops people run into.<\/p>\n<h2>Prerequisites<\/h2>\n<ul>\n<li>A valid SSL certificate that covers every name you redirect to, including <code class=\"\" data-line=\"\">www<\/code>. Load <code class=\"\" data-line=\"\">https:\/\/yourdomain<\/code> and <code class=\"\" data-line=\"\">https:\/\/www.yourdomain<\/code> first; both should show a padlock. If one shows ERR_SSL_PROTOCOL_ERROR instead, <a href=\"https:\/\/hostandtech.com\/kb\/ssl\/fix-err-ssl-protocol-error\/\">fix that first<\/a>. If not, fix that before redirecting (see <a href=\"https:\/\/hostandtech.com\/kb\/ssl\/what-is-ssl-certificate-and-why-you-need-it\/\">what an SSL certificate is and how you get one<\/a>).<\/li>\n<li>Access to cPanel, Plesk, or SSH on your VPS.<\/li>\n<li>A decision on your main hostname: <code class=\"\" data-line=\"\">example.com<\/code> or <code class=\"\" data-line=\"\">www.example.com<\/code>. Either is fine; mixing them is not.<\/li>\n<li>For WordPress sites, the site address already set to <code class=\"\" data-line=\"\">https:\/\/<\/code> in <strong>Settings<\/strong> &gt; <strong>General<\/strong> (see <a href=\"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/\">fixing mixed content after switching to HTTPS<\/a>).<\/li>\n<\/ul>\n<h2>Step-by-Step: Redirect HTTP to HTTPS<\/h2>\n<h3>Step 1: Pick one method and remove the others<\/h3>\n<p>On most sites I&#8217;m asked to fix, there are already two or three HTTPS redirects: the cPanel toggle, a rule in <code class=\"\" data-line=\"\">.htaccess<\/code> and a WordPress plugin, each adding its own hop or fighting the others into a loop. Choose one of the steps below that matches your setup, and remove any older HTTPS redirect you find elsewhere.<\/p>\n<table>\n<thead>\n<tr>\n<th>Your setup<\/th>\n<th>Best method<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>cPanel, simple site<\/td>\n<td>Step 2: Force HTTPS Redirect toggle<\/td>\n<\/tr>\n<tr>\n<td>cPanel, need www and HTTPS in one hop<\/td>\n<td>Step 3: .htaccess rule<\/td>\n<\/tr>\n<tr>\n<td>Plesk (Linux or Windows)<\/td>\n<td>Step 4: Plesk hosting setting<\/td>\n<\/tr>\n<tr>\n<td>VPS with Nginx<\/td>\n<td>Step 5: Nginx server block<\/td>\n<\/tr>\n<tr>\n<td>Windows \/ IIS without Plesk<\/td>\n<td>Step 6: web.config rule<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Step 2: cPanel: turn on Force HTTPS Redirect<\/h3>\n<ol>\n<li>Log in to cPanel and open <strong>Domains<\/strong> (in the Domains section).<\/li>\n<li>Find your domain and switch <strong>Force HTTPS Redirect<\/strong> to <strong>On<\/strong>.<\/li>\n<li>Repeat for any addon domains that should also redirect.<\/li>\n<\/ol>\n<p>If the switch is greyed out, cPanel doesn&#8217;t see a valid certificate for that domain yet. Open <strong>SSL\/TLS Status<\/strong>, click <strong>Run AutoSSL<\/strong>, wait for it to finish, and try again. The toggle only handles HTTP to HTTPS; it doesn&#8217;t change www to non-www, so a visitor on <code class=\"\" data-line=\"\">http:\/\/www.example.com<\/code> may still take two hops. If that matters to you, use Step 3 instead.<\/p>\n<h3>Step 3: .htaccess: redirect HTTP to HTTPS on Apache and LiteSpeed<\/h3>\n<p>Open <code class=\"\" data-line=\"\">public_html\/.htaccess<\/code> in <a href=\"https:\/\/hostandtech.com\/kb\/cpanel\/how-to-use-cpanel-file-manager\/\">cPanel File Manager<\/a> (turn on <strong>Show Hidden Files<\/strong> in Settings). Add this at the very top of the file:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-1\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-1'><code class=\"\" data-line=\"\">RewriteEngine On\nRewriteCond %{REQUEST_URI} !^\/&#092;.well-known\/\nRewriteCond %{HTTPS} off\nRewriteRule ^ https:\/\/%{HTTP_HOST}%{REQUEST_URI} [L,R=301]<\/code><\/pre>\n<\/div>\n<p>The <code class=\"\" data-line=\"\">.well-known<\/code> line keeps certificate validation requests on plain HTTP. Let&#8217;s Encrypt follows redirects, but not every validation method does, and excluding the folder costs nothing.<\/p>\n<p>To force HTTPS <strong>and<\/strong> your main hostname in a single hop, use one of these instead. For <code class=\"\" data-line=\"\">https:\/\/example.com<\/code> (no www):<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-2\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-2'><code class=\"\" data-line=\"\">RewriteEngine On\nRewriteCond %{REQUEST_URI} !^\/&#092;.well-known\/\nRewriteCond %{HTTPS} off [OR]\nRewriteCond %{HTTP_HOST} ^www&#092;. [NC]\nRewriteCond %{HTTP_HOST} ^(?:www&#092;.)?(.+)$ [NC]\nRewriteRule ^ https:\/\/%1%{REQUEST_URI} [L,R=301]<\/code><\/pre>\n<\/div>\n<p>For <code class=\"\" data-line=\"\">https:\/\/www.example.com<\/code>:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-3\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-3'><code class=\"\" data-line=\"\">RewriteEngine On\nRewriteCond %{REQUEST_URI} !^\/&#092;.well-known\/\nRewriteCond %{HTTPS} off [OR]\nRewriteCond %{HTTP_HOST} !^www&#092;. [NC]\nRewriteCond %{HTTP_HOST} ^(?:www&#092;.)?(.+)$ [NC]\nRewriteRule ^ https:\/\/www.%1%{REQUEST_URI} [L,R=301]<\/code><\/pre>\n<\/div>\n<p><strong>Note:<\/strong> on WordPress, put these lines <em>above<\/em> the <code class=\"\" data-line=\"\"># BEGIN WordPress<\/code> block. WordPress rewrites everything between its markers whenever permalinks are saved, and rules placed after its catch-all never run.<\/p>\n<figure class=\"wp-block-image\"><img src=\"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/http-to-https-redirect-one-hop-vs-chain.webp\" alt=\"Diagram comparing a single 301 from http:\/\/www to https:\/\/ with a two-hop redirect chain\" width=\"1200\" height=\"520\" loading=\"lazy\" decoding=\"async\"><figcaption>One 301 that fixes both HTTPS and the hostname is better than a chain of redirects.<\/figcaption><\/figure>\n<h3>Step 4: Plesk: enable the SEO-safe 301 redirect<\/h3>\n<ol>\n<li>Go to <strong>Websites &amp; Domains<\/strong> &gt; your domain &gt; <strong>Hosting &amp; DNS<\/strong> &gt; <strong>Hosting<\/strong>.<\/li>\n<li>Under <strong>Security<\/strong>, choose your certificate and tick <strong>Permanent SEO-safe 301 redirect from HTTP to HTTPS<\/strong>.<\/li>\n<li>Set <strong>Preferred domain<\/strong> to either the www or non-www form, so Plesk also redirects the other one.<\/li>\n<li>Click <strong>OK<\/strong> or <strong>Save<\/strong>.<\/li>\n<\/ol>\n<p>On Plesk for Windows this redirect is a URL Rewrite rule that your site&#8217;s <code class=\"\" data-line=\"\">web.config<\/code> can cancel. If it doesn&#8217;t work, look for a <code class=\"\" data-line=\"\">&lt;clear \/&gt;<\/code> line inside <code class=\"\" data-line=\"\">&lt;rewrite&gt;&lt;rules&gt;<\/code> in <code class=\"\" data-line=\"\">httpdocs\/web.config<\/code> and remove it.<\/p>\n<h3>Step 5: Nginx: add a port 80 server block<\/h3>\n<p>On a VPS running Nginx, give port 80 its own server block that does nothing but redirect. Use your main hostname in the target:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-4\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-4'><code class=\"\" data-line=\"\">server {\n    listen 80;\n    listen [::]:80;\n    server_name example.com www.example.com;\n\n    location \/.well-known\/acme-challenge\/ {\n        root \/var\/www\/example.com;\n    }\n\n    location \/ {\n        return 301 https:\/\/example.com$request_uri;\n    }\n}<\/code><\/pre>\n<\/div>\n<p>If your main hostname is <code class=\"\" data-line=\"\">example.com<\/code>, add a separate HTTPS server block for <code class=\"\" data-line=\"\">www.example.com<\/code> with the same certificate that returns <code class=\"\" data-line=\"\">301 https:\/\/example.com$request_uri<\/code>. Then test and reload:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-5\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-5'><code class=\"\" data-line=\"\">sudo nginx -t &amp;&amp; sudo systemctl reload nginx<\/code><\/pre>\n<\/div>\n<p>If you used Certbot&#8217;s <code class=\"\" data-line=\"\">--nginx<\/code> plugin, it may already have added a redirect for you. Check for an existing <code class=\"\" data-line=\"\">return 301<\/code> before adding another.<\/p>\n<h3>Step 6: IIS: add a URL Rewrite rule to web.config<\/h3>\n<p>On Windows Server with IIS and the URL Rewrite module installed, add this rule inside <code class=\"\" data-line=\"\">&lt;system.webServer&gt;&lt;rewrite&gt;&lt;rules&gt;<\/code> in the site&#8217;s <code class=\"\" data-line=\"\">web.config<\/code>:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-6\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-6'><code class=\"\" data-line=\"\">&lt;rule name=&quot;Redirect to HTTPS&quot; stopProcessing=&quot;true&quot;&gt;\n  &lt;match url=&quot;(.*)&quot; \/&gt;\n  &lt;conditions&gt;\n    &lt;add input=&quot;{HTTPS}&quot; pattern=&quot;^OFF$&quot; \/&gt;\n  &lt;\/conditions&gt;\n  &lt;action type=&quot;Redirect&quot; url=&quot;https:\/\/{HTTP_HOST}\/{R:1}&quot; redirectType=&quot;Permanent&quot; \/&gt;\n&lt;\/rule&gt;<\/code><\/pre>\n<\/div>\n<p>The site also needs an HTTPS binding with a certificate; <a href=\"https:\/\/hostandtech.com\/kb\/windows-server\/how-to-configure-ssl-certificate-iis\/\">configuring an SSL certificate in IIS<\/a> walks through that. On Plesk for Windows, <a href=\"https:\/\/hostandtech.com\/kb\/plesk-windows\/web-config-redirects-url-rewrite-plesk-windows\/\">web.config redirects and URL Rewrite in Plesk<\/a> has more rule examples.<\/p>\n<h3>Step 7: Test the redirect<\/h3>\n<p>Use curl rather than a browser, because browsers cache 301 redirects and will happily show you yesterday&#8217;s behaviour:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-7\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-7'><code class=\"\" data-line=\"\">curl -sI http:\/\/example.com\/some-page\/ | grep -iE &#039;^(HTTP|location)&#039;<\/code><\/pre>\n<\/div>\n<p>You should see:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-8\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-8'><code class=\"\" data-line=\"\">HTTP\/1.1 301 Moved Permanently\nLocation: https:\/\/example.com\/some-page\/<\/code><\/pre>\n<\/div>\n<p>Then count the hops from the worst-case address (HTTP plus the hostname you <em>don&#8217;t<\/em> use):<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-9\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-9'><code class=\"\" data-line=\"\">curl -sIL -o \/dev\/null -w &#039;%{num_redirects} hop(s) to %{url_effective}&#092;n&#039; http:\/\/www.example.com\/<\/code><\/pre>\n<\/div>\n<p>The answer should be <code class=\"\" data-line=\"\">1 hop(s) to https:\/\/example.com\/<\/code>. Two hops still work, but every extra redirect adds a round trip on slow mobile connections.<\/p>\n<h3>Step 8 (optional): Add HSTS once everything works<\/h3>\n<p>HSTS tells browsers to go straight to HTTPS without asking over HTTP first. Start with a short lifetime, and raise it after a week with no problems. In <code class=\"\" data-line=\"\">.htaccess<\/code>:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-10\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-10'><code class=\"\" data-line=\"\">Header always set Strict-Transport-Security &quot;max-age=300&quot;<\/code><\/pre>\n<\/div>\n<p><strong>Warning:<\/strong> once a browser has seen a long HSTS lifetime, you can&#8217;t go back to HTTP for that domain until it expires. Don&#8217;t add <code class=\"\" data-line=\"\">includeSubDomains<\/code> or <code class=\"\" data-line=\"\">preload<\/code> until every subdomain, including mail and staging hosts, has a working certificate.<\/p>\n<h2>Common Issues &amp; Troubleshooting<\/h2>\n<h3>ERR_TOO_MANY_REDIRECTS<\/h3>\n<p><strong>Cause:<\/strong> two redirects are fighting (for example a www rule in <code class=\"\" data-line=\"\">.htaccess<\/code> and the opposite Preferred domain in Plesk), or a CDN or proxy talks to your server over HTTP, so the server keeps seeing <code class=\"\" data-line=\"\">HTTPS off<\/code> and redirecting again. The classic case is a CDN set to a &#8220;flexible&#8221; SSL mode.<\/p>\n<p><strong>Fix:<\/strong> remove every redirect except the one you chose in Step 1. If a CDN sits in front, set it to connect to your server over HTTPS with full certificate checking, so the server sees HTTPS requests. Then clear the browser cache or test with curl.<\/p>\n<h3>The redirect does nothing<\/h3>\n<p><strong>Cause:<\/strong> the rule is in the wrong <code class=\"\" data-line=\"\">.htaccess<\/code> (an addon domain has its own document root), <code class=\"\" data-line=\"\">.htaccess<\/code> is ignored because the server runs Nginx only, or on your own Apache server <code class=\"\" data-line=\"\">AllowOverride<\/code> is set to <code class=\"\" data-line=\"\">None<\/code>.<\/p>\n<p><strong>Fix:<\/strong> check the domain&#8217;s document root in cPanel&#8217;s <strong>Domains<\/strong> page and edit the <code class=\"\" data-line=\"\">.htaccess<\/code> in that folder. On a VPS, use the server config (Step 5) or set <code class=\"\" data-line=\"\">AllowOverride All<\/code> for the site&#8217;s directory.<\/p>\n<h3>AutoSSL or Let&#8217;s Encrypt renewal fails after adding the redirect<\/h3>\n<p><strong>Cause:<\/strong> the validation request for <code class=\"\" data-line=\"\">\/.well-known\/<\/code> is being redirected somewhere it can&#8217;t be answered, often to a different hostname.<\/p>\n<p><strong>Fix:<\/strong> keep the <code class=\"\" data-line=\"\">.well-known<\/code> exclusion from Step 3 (or the Nginx <code class=\"\" data-line=\"\">location<\/code> in Step 5), then rerun AutoSSL. The <a href=\"https:\/\/hostandtech.com\/kb\/ssl\/ssl-certificate-not-renewing-fix\/\">SSL renewal troubleshooting guide<\/a> covers the other causes.<\/p>\n<h3>Search Console still shows http:\/\/ pages<\/h3>\n<p><strong>Cause:<\/strong> Google recrawls old URLs gradually, and internal links, the sitemap or canonical tags still use <code class=\"\" data-line=\"\">http:\/\/<\/code>.<\/p>\n<p><strong>Fix:<\/strong> update internal links and the site URL setting to <code class=\"\" data-line=\"\">https:\/\/<\/code>, make sure the sitemap lists HTTPS addresses only, and give it a few weeks. A clean 301 passes the old URL&#8217;s ranking to the new one.<\/p>\n<p>Hosting that handles certificates for you saves most of this work: <a href=\"https:\/\/hostandtech.com\/cloudlinux-cpanel-shared-hosting\">Host &amp; Tech cPanel hosting<\/a> issues free AutoSSL certificates for every domain on the account, so the Force HTTPS switch is available as soon as the domain points at us.<\/p>\n<div class=\"ht-faq-section\">\n<h2>Frequently Asked Questions<\/h2>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">Should I use a 301 or 302 redirect for HTTPS?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>Use a 301 (permanent) redirect. It tells search engines the HTTPS address has replaced the HTTP one, so rankings move across. A 302 is only for temporary moves and is useful while testing, because browsers don&#8217;t cache it as hard.<\/p>\n<\/div>\n<\/div>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">Does redirecting HTTP to HTTPS hurt SEO?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>No. A single 301 to the HTTPS version is what Google expects, and HTTPS is a small ranking signal in its own right. What hurts is redirect chains, loops, and internal links or sitemaps that still point at http:\/\/ addresses.<\/p>\n<\/div>\n<\/div>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">Why is the Force HTTPS Redirect switch greyed out in cPanel?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>cPanel only enables it when the domain has a valid certificate. Open SSL\/TLS Status, click Run AutoSSL and wait for it to finish. If AutoSSL fails, the domain usually doesn&#8217;t point at the server yet or a DNS record is wrong.<\/p>\n<\/div>\n<\/div>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">Do I need a plugin to force HTTPS in WordPress?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>No. Set both addresses in Settings &gt; General to https:\/\/, then use the cPanel switch or the .htaccess rule. Plugins that force HTTPS add a PHP-level redirect on top of the server one, which is slower and is a common source of redirect loops.<\/p>\n<\/div>\n<\/div>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">Do I still need a redirect if I use HSTS?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>Yes. HSTS only works after a browser has visited the site over HTTPS at least once, and search engines and first-time visitors still arrive on http:\/\/ links. The 301 handles them; HSTS then speeds up repeat visits.<\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Send every visitor to the HTTPS version of your site with a single 301: the cPanel and Plesk switches, copy-ready rules for .htaccess, Nginx and IIS, how to do www and HTTPS in one hop, and how to fix ERR_TOO_MANY_REDIRECTS.<\/p>\n","protected":false},"author":1,"featured_media":271,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[79],"tags":[691,40,125,81,85,154],"class_list":["post-277","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ssl","tag-301-redirect","tag-cpanel","tag-htaccess","tag-https","tag-iis","tag-nginx"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Redirect HTTP to HTTPS (cPanel, .htaccess, Nginx)<\/title>\n<meta name=\"description\" content=\"Redirect HTTP to HTTPS with one clean 301: cPanel and Plesk toggles, copy-ready .htaccess, Nginx and IIS rules, a curl test and redirect loop fixes.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Redirect HTTP to HTTPS (cPanel, .htaccess, Nginx)\" \/>\n<meta property=\"og:description\" content=\"Redirect HTTP to HTTPS with one clean 301: cPanel and Plesk toggles, copy-ready .htaccess, Nginx and IIS rules, a curl test and redirect loop fixes.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/\" \/>\n<meta property=\"og:site_name\" content=\"Host And Tech knowledge base\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/stshostandtech\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-27T17:05:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/force-https-redirect-http-to-https.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@stshostandtech\" \/>\n<meta name=\"twitter:site\" content=\"@stshostandtech\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#\\\/schema\\\/person\\\/b6fa79c48ddaba71af32e395c5b017ee\"},\"headline\":\"How to Force HTTPS: Redirect HTTP to HTTPS in cPanel, Plesk, .htaccess, Nginx and IIS\",\"datePublished\":\"2026-09-27T17:05:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/\"},\"wordCount\":1533,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/force-https-redirect-http-to-https.webp\",\"keywords\":[\"301 redirect\",\"cPanel\",\"htaccess\",\"https\",\"IIS\",\"nginx\"],\"articleSection\":[\"SSL &amp; HTTPS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/\",\"name\":\"How to Redirect HTTP to HTTPS (cPanel, .htaccess, Nginx)\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/force-https-redirect-http-to-https.webp\",\"datePublished\":\"2026-09-27T17:05:05+00:00\",\"description\":\"Redirect HTTP to HTTPS with one clean 301: cPanel and Plesk toggles, copy-ready .htaccess, Nginx and IIS rules, a curl test and redirect loop fixes.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/#primaryimage\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/force-https-redirect-http-to-https.webp\",\"contentUrl\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/force-https-redirect-http-to-https.webp\",\"width\":1200,\"height\":630,\"caption\":\"Title card: redirect HTTP to HTTPS with a single 301 using .htaccess and test it with curl\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/force-https-redirect-http-to-https\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Force HTTPS: Redirect HTTP to HTTPS in cPanel, Plesk, .htaccess, Nginx and IIS\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#website\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/\",\"name\":\"Host And Tech knowledge base\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#organization\",\"name\":\"Host And Tech knowledge base\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/logo-dark.png\",\"contentUrl\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/logo-dark.png\",\"width\":1134,\"height\":395,\"caption\":\"Host And Tech knowledge base\"},\"image\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/stshostandtech\",\"https:\\\/\\\/x.com\\\/stshostandtech\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#\\\/schema\\\/person\\\/b6fa79c48ddaba71af32e395c5b017ee\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\\\/\\\/hostandtech.com\\\/kb\"],\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/author\\\/admin_fjj7qydm\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Redirect HTTP to HTTPS (cPanel, .htaccess, Nginx)","description":"Redirect HTTP to HTTPS with one clean 301: cPanel and Plesk toggles, copy-ready .htaccess, Nginx and IIS rules, a curl test and redirect loop fixes.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/","og_locale":"en_US","og_type":"article","og_title":"How to Redirect HTTP to HTTPS (cPanel, .htaccess, Nginx)","og_description":"Redirect HTTP to HTTPS with one clean 301: cPanel and Plesk toggles, copy-ready .htaccess, Nginx and IIS rules, a curl test and redirect loop fixes.","og_url":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/","og_site_name":"Host And Tech knowledge base","article_publisher":"https:\/\/www.facebook.com\/stshostandtech","article_published_time":"2026-09-27T17:05:05+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/force-https-redirect-http-to-https.webp","type":"image\/webp"}],"author":"admin","twitter_card":"summary_large_image","twitter_creator":"@stshostandtech","twitter_site":"@stshostandtech","twitter_misc":{"Written by":"admin","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/#article","isPartOf":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/"},"author":{"name":"admin","@id":"https:\/\/hostandtech.com\/kb\/#\/schema\/person\/b6fa79c48ddaba71af32e395c5b017ee"},"headline":"How to Force HTTPS: Redirect HTTP to HTTPS in cPanel, Plesk, .htaccess, Nginx and IIS","datePublished":"2026-09-27T17:05:05+00:00","mainEntityOfPage":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/"},"wordCount":1533,"commentCount":0,"publisher":{"@id":"https:\/\/hostandtech.com\/kb\/#organization"},"image":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/#primaryimage"},"thumbnailUrl":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/force-https-redirect-http-to-https.webp","keywords":["301 redirect","cPanel","htaccess","https","IIS","nginx"],"articleSection":["SSL &amp; HTTPS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/","url":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/","name":"How to Redirect HTTP to HTTPS (cPanel, .htaccess, Nginx)","isPartOf":{"@id":"https:\/\/hostandtech.com\/kb\/#website"},"primaryImageOfPage":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/#primaryimage"},"image":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/#primaryimage"},"thumbnailUrl":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/force-https-redirect-http-to-https.webp","datePublished":"2026-09-27T17:05:05+00:00","description":"Redirect HTTP to HTTPS with one clean 301: cPanel and Plesk toggles, copy-ready .htaccess, Nginx and IIS rules, a curl test and redirect loop fixes.","breadcrumb":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/#primaryimage","url":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/force-https-redirect-http-to-https.webp","contentUrl":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/force-https-redirect-http-to-https.webp","width":1200,"height":630,"caption":"Title card: redirect HTTP to HTTPS with a single 301 using .htaccess and test it with curl"},{"@type":"BreadcrumbList","@id":"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/hostandtech.com\/kb\/"},{"@type":"ListItem","position":2,"name":"How to Force HTTPS: Redirect HTTP to HTTPS in cPanel, Plesk, .htaccess, Nginx and IIS"}]},{"@type":"WebSite","@id":"https:\/\/hostandtech.com\/kb\/#website","url":"https:\/\/hostandtech.com\/kb\/","name":"Host And Tech knowledge base","description":"","publisher":{"@id":"https:\/\/hostandtech.com\/kb\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/hostandtech.com\/kb\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/hostandtech.com\/kb\/#organization","name":"Host And Tech knowledge base","url":"https:\/\/hostandtech.com\/kb\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/hostandtech.com\/kb\/#\/schema\/logo\/image\/","url":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/05\/logo-dark.png","contentUrl":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/05\/logo-dark.png","width":1134,"height":395,"caption":"Host And Tech knowledge base"},"image":{"@id":"https:\/\/hostandtech.com\/kb\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/stshostandtech","https:\/\/x.com\/stshostandtech"]},{"@type":"Person","@id":"https:\/\/hostandtech.com\/kb\/#\/schema\/person\/b6fa79c48ddaba71af32e395c5b017ee","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/hostandtech.com\/kb"],"url":"https:\/\/hostandtech.com\/kb\/author\/admin_fjj7qydm\/"}]}},"_links":{"self":[{"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/posts\/277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/comments?post=277"}],"version-history":[{"count":1,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/posts\/277\/revisions"}],"predecessor-version":[{"id":281,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/posts\/277\/revisions\/281"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/media\/271"}],"wp:attachment":[{"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/media?parent=277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/categories?post=277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/tags?post=277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}