October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Apache

How to Redirect Old URLs with redirect.php (and When Apache Is Better)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a PHP Location header when your application must decide where an obsolete URL goes. For a fixed one-to-one mapping, an Apache server-level Redirect is usually simpler and runs before PHP. Both are external HTTP redirects: the server returns a 3xx response, the client requests the destination, and the browser’s address changes. An internal rewrite is different—it serves another resource while keeping the original URL visible.

Choose the right layer first

Option Best for Browser URL Access required Main considerations
Apache Redirect or RedirectMatch Fixed path or pattern mappings Changes Virtual-host/server configuration (or an available .htaccess context) Straightforward and avoids booting the application
Apache mod_rewrite Conditions, host/scheme checks, or complex patterns Changes for redirect rules; can remain unchanged for internal rewrites Rewrite configuration access Powerful, but more complex; validate rules carefully
PHP redirect.php Destination depends on application logic, database state, or a fixed map in code Changes Ability to route the legacy request to PHP Headers must precede output, and execution must stop after redirecting
Internal rewrite Serve a new file or route without exposing a new public URL Stays the same Rewrite configuration or framework routing It is not an HTTP redirect and does not tell the client to navigate elsewhere

Apache’s guidance recommends Redirect or RedirectMatch for simple redirects and mod_rewrite when conditions are required: Apache redirect and remapping documentation and when not to use mod_rewrite.

Implement a fixed mapping in redirect.php

Route the obsolete request to this script, set an explicit status, and terminate immediately:

<?php
// redirect.php — fixed legacy URL mapping
$destination = '/new-page/';

header('Location: ' . $destination, true, 301);
exit;

The relative path keeps this example on the current origin. Do not replace it with an arbitrary value from a query parameter. PHP’s header() must execute before HTML, whitespace, a byte-order mark, or any other output; otherwise the header may fail. After sending Location, exit prevents later application code from generating a second response. See the PHP header() manual.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Routing the old path to PHP

Your web server or framework must actually dispatch the legacy URL to redirect.php. A script that exists but is never selected for the old path cannot redirect it. Keep the mapping explicit—for example, map /old-page to this script—rather than creating a catch-all endpoint that reflects user input.

Use Apache when the mapping is static

If you can edit the virtual-host configuration, Apache’s documented simple form is:

Redirect "/old-path" "/new-path"

This is generally preferable to sending a fixed request through PHP. A server administrator may need to reload Apache, and rules available in a virtual host are not identical to those permitted in .htaccess. Use RedirectMatch or mod_rewrite when you need regular expressions, conditions, host checks, or scheme logic. Apache warns that the power of mod_rewrite brings potential security mistakes: security considerations.

Redirect versus internal rewrite

External HTTP redirect

The response contains a 3xx status and a Location destination. The client makes a new request, and the address bar changes. This is the correct behavior when an old public URL has moved and visitors should use the new URL.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Internal rewrite

The server maps the request to another file or route internally and returns that resource without instructing the client to navigate. The address bar remains the old URL. Choose this only when keeping the public URL is intentional.

Select the status code deliberately

Status Use Method behavior and caveats
301 Permanent move Cacheable by default under RFC 7231; avoid it for a temporary experiment
302 Temporary move PHP’s normal default for Location when no relevant status was already set
303 Tell the client to retrieve the destination with GET Useful after a non-GET action when the follow-up should be a retrieval
307 Temporary move while preserving the request method Consider when a POST, PUT, or other method must remain that method
308 Permanent move while preserving the request method Use only when permanence and method preservation are both intended

Pass the chosen code as the third argument to header(), for example header('Location: /new-page/', true, 302);. PHP’s default and header-order behavior are documented in its manual; status semantics and caching rules are defined in RFC 7231 (June 2014). Clients and caches can have their own policies, so select permanence and method behavior based on the real migration.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Prevent open redirects

Never build a general-purpose endpoint that blindly sends visitors to a URL supplied in $_GET, a form field, or another untrusted request value. An attacker can turn such an endpoint into a link that appears to belong to your site but lands on a malicious host. Prefer a fixed mapping:

$routes = [
    '/old-page' => '/new-page/',
    '/legacy-help' => '/support/',
];

$path = parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH);
if (isset($routes[$path])) {
    header('Location: ' . $routes[$path], true, 301);
    exit;
}
http_response_code(404);

If business requirements demand selectable destinations, validate against a strict allowlist of complete, expected targets; do not accept any hostname merely because it appears syntactically valid. Apache’s security documentation identifies unvalidated redirect targets as an open-redirect risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Handle HTTP-to-HTTPS and proxies correctly

For a direct HTTP-to-HTTPS migration, Apache recommends placing a Redirect in the dedicated HTTP virtual host. When TLS terminates at a load balancer or reverse proxy, the backend’s %{HTTPS} value may not describe the visitor’s original connection. Trust X-Forwarded-Proto only when a proxy you control overwrites that header; otherwise clients can forge it. Apache documents this topology and remapping behavior at Redirecting and Remapping with mod_rewrite.

Query strings, chains, and loops

Decide whether the destination needs the old query string. Apache rewrite rules can preserve, append, or discard query parameters; specify the intended behavior instead of assuming it. Point each obsolete path directly to its final destination where practical to avoid redirect chains, and check rules for loops such as a destination that matches the old-path rule again.

Verify the deployment

  1. Request the old URL with a browser network panel or HTTP client and inspect the first response status and Location header.
  2. Confirm the destination’s path, scheme, host, and query-string behavior are intentional.
  3. Follow the redirect and verify the final response. Repeat with a POST when method preservation matters.
  4. If code accepts a destination parameter, try an external hostname and confirm it is rejected unless explicitly allowlisted.
  5. Check that no output—including whitespace or a byte-order mark—precedes header(), and that execution stops after the redirect.

A practical command-line check is:

curl -i https://example.com/old-page

Look for the first status line and Location:; use curl -I -L when you also want to inspect the redirect chain and final response.

Recommended decision

For one fixed old-to-new path, configure Apache’s Redirect if you have server access. Use redirect.php when routing or destination selection genuinely belongs to PHP, and hard-code or strictly allowlist every destination. Choose 301 or 308 only for a move intended to be permanent; use 302, 303, or 307 when the move is temporary or its request-method behavior requires it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.