DNS, Security & Integrations
Force HTTP to HTTPS via Server Rules
Set up a proper server-level redirect so every visitor lands on HTTPS, with no exceptions.
The Problem
An SSL certificate being installed doesn't mean visitors are actually forced onto it — without a proper redirect rule, plenty of traffic (and search engines) can still land on the insecure HTTP version.
About this problem
Installing an SSL certificate only makes HTTPS available; it does not make anyone use it. Without a redirect, the HTTP version of the site keeps answering, so visitors, old links and search engines can still reach it, and search engines may index duplicate versions. A server-level 301 redirect solves this by sending every request to the secure URL.
People look for this after installing a certificate and finding that the padlock is missing on some URLs, or after an SEO or security audit. The common trap is redirect loops when a CDN or proxy such as Cloudflare also handles HTTPS, so the rule must be written with that setup in mind.
What's Included
- Setting up a correct 301 redirect at the server/.htaccess/Nginx level
- Making sure the rule doesn't create a redirect loop with your CDN/proxy if you have one
- Checking HSTS is sensible if you want it enabled
- Verifying every entry point (www, non-www, specific pages) redirects correctly
What's NOT Included
- Purchasing/installing the SSL certificate itself (assumes one is active)
- CDN-level redirect configuration, if that's where it needs to live instead
- Mixed content fixes beyond the redirect itself (separate service)
How It Works
- I check how the site currently responds on HTTP and HTTPS for the www and non-www versions.
- I identify the server type (Apache, Nginx or other) and where redirect rules should live.
- I add a 301 redirect rule to .htaccess or the server configuration that sends HTTP to HTTPS and preserves the path and query string.
- I make sure the rule respects any CDN or proxy headers so it does not create a redirect loop.
- I check whether HSTS is appropriate and, if you want it, add it with a sensible max-age.
- I test every entry point (http and https, www and non-www, deep URLs) to confirm a single clean redirect.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- How do I force HTTPS on my website?
- With a server-level 301 redirect from HTTP to HTTPS, which I set up in .htaccess or the Nginx configuration.
- Why do I get a redirect loop after forcing HTTPS?
- It usually happens when a CDN connects to the origin over HTTP and the origin redirects back to HTTPS. The rule has to take the proxy's headers into account.
- Do I need HSTS?
- It is useful once HTTPS works everywhere, but it is hard to undo, so I only add it if you want it and the site is ready.
- Do you install the SSL certificate too?
- No. This service assumes a valid certificate is already active.
- I still see mixed content warnings after the redirect.
- Mixed content comes from resources loaded over HTTP inside pages, which a redirect does not fix. That is a separate service.
- What if my redirect should be handled in Cloudflare instead?
- CDN-level redirect configuration is not covered here, though I will tell you if that is the better place for it.