How do I force HTTPS on my website?
Server-Side Redirects
The most reliable way is to add a 301 redirect from HTTP to HTTPS in your server configuration. For Apache, edit your .htaccess file with a RewriteRule. For Nginx, use a server block that listens on port 80 and returns a 301 redirect to the HTTPS version.
If you use a control panel like cPanel, look for a 'Force HTTPS' option or use the redirect tool. After setting up, test with a tool like Redirect Checker to ensure all URLs redirect correctly.
- Apache: Add `RewriteEngine On`, `RewriteCond %{HTTPS} off`, `RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]` to .htaccess.
- Nginx: In the server block for port 80, add `return 301 https://$host$request_uri;`.
- CDN: Many CDNs (e.g., Cloudflare) have a one-click 'Always Use HTTPS' option.
- CMS: WordPress users can set the site URL to HTTPS in Settings > General, or use a plugin like Really Simple SSL.
Additional Steps
Update all internal links, including those in menus, widgets, and hardcoded URLs, to use HTTPS. Otherwise, you may get mixed content warnings. Consider implementing HTTP Strict Transport Security (HSTS) to tell browsers to only use HTTPS for your site, but be cautious as it's difficult to undo.
After forcing HTTPS, check for any remaining HTTP resources using your browser's developer tools (Console tab). Fix them by updating the URLs or using protocol-relative URLs (//example.com).
Common mistakes
- Only redirecting the homepage while other pages remain accessible via HTTP.
- Enabling HSTS before ensuring all subdomains support HTTPS, which can lock users out.
- Forgetting to update mixed content, leading to broken padlocks and security warnings.
