Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To redirect a website from HTTP to HTTPS, first make sure the site already loads over HTTPS with a valid TLS certificate. Then configure the web server listening on port 80 to send a permanent redirect to the same hostname, path, and query string over HTTPS. For ordinary webpages, use a 301 redirect. Use 308 instead when a request’s method and body must be preserved, as is often important for API traffic.

Before you redirect: make sure HTTPS works

A redirect does not provide encryption or make a certificate valid. It only tells a browser where to go. The HTTPS destination must be configured and reachable first, or visitors redirected to it will see a certificate warning or an unavailable site.

  1. Obtain and install a certificate for every hostname the site serves, such as the apex domain and www hostname if both are in use. Protect the private key. NGINX’s documentation notes that the key must be readable by the NGINX master process.
  2. Configure the HTTPS virtual host or server block to serve the intended site. Check the canonical hostname, pages, cookies, and static assets over HTTPS before changing HTTP behavior.
  3. Confirm that certificate issuance and renewal will continue to work. ACME clients such as Certbot may need HTTP access to /.well-known/acme-challenge/; do not block that path if your validation setup depends on it.

For a managed host or CDN, the equivalent work may be done in its TLS, domain, or redirect settings rather than in Apache or NGINX configuration files. Follow the provider’s instructions for installing the certificate and keep its renewal process working.

Choose 301 or 308

Status Use it for Request behavior
301 Moved Permanently Ordinary website navigation and page URLs GET requests remain GET. User agents may change other methods, such as POST, during the redirect.
308 Permanent Redirect Permanent redirects where preserving the request method and body matters, such as API operations Preserves the method and body.

MDN documents these status-code semantics. A 301 is the normal choice for moving a website to HTTPS. If clients send POST or PUT requests to an endpoint and the operation must arrive with the same method and body, use 308 and verify the behavior with the actual clients.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the HTTP-to-HTTPS redirect

NGINX

Use a dedicated port-80 server block. This example keeps the requested hostname, path, and query string:

server {
    listen 80;
    server_name example.com www.example.com;

    return 301 https://$host$request_uri;
}

Replace the example hostnames with the names this server is intended to handle. NGINX’s $request_uri includes the path and query string, so a request such as http://example.com/article?id=7 is sent to https://example.com/article?id=7. For a method-preserving permanent redirect, change 301 to 308.

Do not use this exact host-preserving pattern blindly if the HTTP request’s Host header can be arbitrary or untrusted. Configure the server names and default server behavior deliberately, and use a fixed canonical destination when that better matches your hostname policy.

Apache with mod_alias

For a straightforward whole-site redirect, Apache’s Redirect permanent directive can be used in the appropriate virtual host or directory configuration:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Redirect permanent / https://example.org/

Choose the destination hostname you actually intend to serve. A fixed destination is useful when consolidating www and apex hostnames, but it means the first redirect can change both scheme and hostname. If each hostname should remain itself, configure the hosts separately rather than sending all requests to one unexamined destination.

Apache with mod_rewrite

Apache’s mod_rewrite documentation gives this permanent HTTPS pattern:

RewriteEngine On
RewriteRule "^(.*)" "https://%{SERVER_NAME}$1" [R=301,L]

Place the rule in the correct virtual-host or directory context and confirm how that context handles the path prefix. If preserving methods is required for an API, use an appropriate 308 redirect instead of 301 and test it with the clients that call the endpoint. Ensure certificate-validation requests to /.well-known/acme-challenge/ remain reachable when your ACME setup requires them.

Other hosting setups

On IIS or a managed edge service, configure a permanent scheme redirect in the site’s HTTPS/redirect or rule settings, using the provider’s current interface. The important result is the same: port-80 requests reach a valid HTTPS endpoint, with the intended hostname and original path preserved. Check whether the host has already enabled an HTTPS redirect; adding a second rule can create a chain or loop.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Preserve hostnames, paths, and certificate coverage

Decide whether the canonical hostname is the apex domain, such as example.com, or a subdomain such as www.example.com. A user may arrive through HTTP on either host, and the certificate must cover the HTTPS hostname the redirect sends them to.

  • To keep each hostname, use a redirect that retains the incoming host only when the server accepts and safely handles those hosts.
  • To consolidate hostnames, send each non-canonical host to the canonical HTTPS host and preserve its path and query string.
  • Test both slash and no-slash paths, query strings, and important endpoints. Avoid a sequence such as HTTP apex → HTTPS apex → HTTPS www when a single redirect can reach the final URL.

Changing both scheme and hostname can be appropriate, but the final destination must have a valid certificate and serve the requested content. Test the first HTTP response and the final HTTPS response rather than assuming the server’s rules combine as intended.

Test the redirect before enabling HSTS

Start with representative URLs, including the homepage, a nested page, a query-string URL, and any API endpoint where method behavior matters. From a terminal, inspect the initial response:

curl -I "http://example.com/article?ref=test"

For an ordinary page, expect a permanent redirect status such as 301 and a Location header with the intended HTTPS URL. Then check the destination:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -I "https://example.com/article?ref=test"

The HTTPS request should succeed without a certificate error and return the expected page response. If you need to inspect the complete redirect chain, use:

curl -IL "http://example.com/article?ref=test"

Look for a single hop to the correct HTTPS destination where practical. Also test in a browser: inspect the final URL and developer tools’ Console and Network panels for failed resources and mixed-content warnings. A page can load over HTTPS while still requesting images, scripts, stylesheets, or other resources over HTTP.

For an endpoint that must preserve a POST, test with a non-production request or safe test endpoint. Confirm that the client receives the intended status and that the final request still uses the expected method and body. Do not assume all clients handle redirects identically.

Enable HSTS only when the HTTPS setup is stable

HTTP Strict Transport Security (HSTS) tells a browser that has received the policy over HTTPS to use HTTPS for future visits. For example, an HTTPS response can include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Strict-Transport-Security: max-age=31536000; includeSubDomains

Browsers ignore HSTS headers received over HTTP. HSTS also cannot protect the first connection by itself: a browser that has not yet received the HTTPS policy can still make an initial HTTP request. The HTTP-to-HTTPS redirect remains necessary for that case.

Begin with a policy appropriate to your readiness, and add includeSubDomains only if every subdomain is reliably available over HTTPS. Browsers applying that directive will expect HTTPS across those subdomains too. A forgotten service or hostname that cannot serve HTTPS can become inaccessible to affected browsers. Do not treat a long max-age or broader subdomain policy as a harmless default.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common failures

Certificate warning after the redirect

Cause: The certificate is missing, expired, untrusted, or does not cover the hostname in the redirect’s Location. Fix: Install or renew a certificate covering that exact hostname, and verify the HTTPS virtual host serves it before redirecting traffic there.

Redirect loop

Cause: Two layers disagree about whether the request is HTTP or HTTPS, or the HTTPS endpoint redirects back to HTTP. This can also happen when a proxy or CDN terminates TLS but the origin receives a request that it interprets as HTTP. Fix: Identify every redirect layer, inspect the chain with curl -IL, and configure the edge and origin consistently so HTTPS requests are not sent back to HTTP.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Path or query string disappears

Cause: The rule redirects every request to the HTTPS homepage or omits the original URI. Fix: Preserve the request URI in NGINX with $request_uri, or adjust the Apache or managed-host rule so it retains the original path and query string. Test nested URLs, not just the homepage.

POST or PUT arrives as GET

Cause: A 301 redirect can lead user agents to change a non-GET method. Fix: If method and body preservation is required, use 308 and verify the behavior with the actual API clients.

Certificate renewal fails

Cause: The redirect or access controls prevent an ACME client from reaching its HTTP challenge path. Fix: Keep /.well-known/acme-challenge/ available in the manner required by the certificate-validation method, and test renewal rather than only initial issuance.

HTTPS page shows mixed-content or missing assets

Cause: The page still references resources with HTTP URLs, or an asset host is not configured for HTTPS. Fix: Update resource URLs to HTTPS (or use appropriate relative URLs), confirm each asset hostname has a valid certificate, and check the browser Console and Network panels for blocked requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Too many redirects between hostnames

Cause: Separate rules normalize the scheme and hostname in multiple hops, or they disagree about the canonical hostname. Fix: Choose one canonical host and configure each accepted HTTP hostname to reach its final HTTPS URL directly where possible. Check apex and www variants separately.

Or skip the browser setup

If your goal is to capture a clean screenshot of a page after making the change, ScreenshotNeo provides a website screenshot API and MCP server. Its cleanup can accept cookie or consent banners and remove supported consent platforms, newsletter popups, and chat widgets before capture; those cleanup steps can be turned off. It does not bill bot checks or CAPTCHAs, blank pages, timeouts, failed loads, or cache hits, and responses identify the page verdict and billing status in headers. AI agents can use its MCP tools, including take_screenshot, get_page_info, and capture_pdf.

One GET request returns a screenshot or PDF. For example, this cURL call captures the final HTTPS page as WebP:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

See the ScreenshotNeo API documentation for request options and response details. ScreenshotNeo offers 1,000 screenshots per month free with no card; paid plans start at $5 for 3,000 screenshots. Sign up for the free plan.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Operational notes

A permanent redirect is intended to communicate that the move is lasting, so test the rule before relying on it and be cautious about changing an established canonical-host policy. Keep certificate renewal monitored, and retest representative URLs after changes to the web server, proxy, CDN, or hostname configuration. The official guidance cited here specifies protocol behavior and configuration patterns, not a universal performance benchmark; actual latency depends on the server and network path.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.