The .htaccess file controls how Apache handles requests for your site. It manages redirects, custom error pages, caching, and access rules. A single syntax error can take the whole site offline, so edit it carefully.
Finding the File
- Open File Manager from the Files section in cPanel.
- Open the
public_htmlfolder. - Click Settings in the top right and enable Show Hidden Files, then Save.
- Look for
.htaccess. If it is missing, click +File and create one named exactly.htaccess.
Editing Safely
- Right-click
.htaccessand choose Copy to make a backup, naming ithtaccess-backup. - Right-click the original and choose Edit.
- Make your change and click Save Changes.
- Reload your site in a private browser window to test it.
If the site breaks, restore the backup copy immediately.
Common Rules
Force HTTPS for every visitor:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]
Block access to a folder:
<RequireAll>
Require all denied
</RequireAll>
Troubleshooting
- A 500 Internal Server Error usually means a typo in
.htaccess. Rename the file to disable it, then fix the line. - Rules are read top to bottom, so order matters for redirects.
- Some applications, including WordPress, manage their own block in this file. Keep your custom rules outside the
# BEGINand# ENDmarkers.
If you are unsure about a rule, contact support through the /contact page before applying it to a live site.