How do I force HTTPS on my website?

Updated October 2026 · How we answer

Short answerForce HTTPS by redirecting all HTTP traffic to HTTPS using server-side rules (e.g., .htaccess or Nginx config) or a CDN setting. Also update internal links and use HSTS for added security.

Server-Side Redirects

The most reliable way is to add a 301 redirect from HTTP to HTTPS in your server configuration. For Apache, edit your .htaccess file with a RewriteRule. For Nginx, use a server block that listens on port 80 and returns a 301 redirect to the HTTPS version.

If you use a control panel like cPanel, look for a 'Force HTTPS' option or use the redirect tool. After setting up, test with a tool like Redirect Checker to ensure all URLs redirect correctly.

  • Apache: Add `RewriteEngine On`, `RewriteCond %{HTTPS} off`, `RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]` to .htaccess.
  • Nginx: In the server block for port 80, add `return 301 https://$host$request_uri;`.
  • CDN: Many CDNs (e.g., Cloudflare) have a one-click 'Always Use HTTPS' option.
  • CMS: WordPress users can set the site URL to HTTPS in Settings > General, or use a plugin like Really Simple SSL.

Additional Steps

Update all internal links, including those in menus, widgets, and hardcoded URLs, to use HTTPS. Otherwise, you may get mixed content warnings. Consider implementing HTTP Strict Transport Security (HSTS) to tell browsers to only use HTTPS for your site, but be cautious as it's difficult to undo.

After forcing HTTPS, check for any remaining HTTP resources using your browser's developer tools (Console tab). Fix them by updating the URLs or using protocol-relative URLs (//example.com).

Common mistakes

  • Only redirecting the homepage while other pages remain accessible via HTTP.
  • Enabling HSTS before ensuring all subdomains support HTTPS, which can lock users out.
  • Forgetting to update mixed content, leading to broken padlocks and security warnings.
From our shopsSwiftCase: Curated phone cases that ship in 48 hours.