How to Force HTTPS on Your Website

Redirect all HTTP traffic to HTTPS using cPanel or .htaccess so visitors always load the secure version of your site.

· Updated · 3,923 views

Once you have an SSL certificate installed, you should force every request to use HTTPS. Otherwise visitors can still reach the insecure http:// version, which shows a "Not Secure" warning and weakens your security.

Use the cPanel Toggle

The easiest method requires no editing:

  1. Log in to cPanel.
  2. Open Domains under the Domains section.
  3. Find your domain in the list.
  4. Switch the Force HTTPS Redirect toggle to on.

This adds a server-level redirect for that domain immediately.

Force HTTPS with .htaccess

If your hosting setup does not show the toggle, add a redirect rule to the .htaccess file in your public_html folder. Place these lines at the top, above any existing WordPress rules:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

The R=301 flag makes the redirect permanent, which is best for SEO.

Update Your Site Settings

A redirect alone is not always enough:

  • In WordPress, set both the Site Address and WordPress Address to https:// under Settings, General.
  • Update any hardcoded http:// links in your theme or content.
  • Update the canonical URL in any SEO plugin.

Verify the Redirect

  1. Open a private browser window.
  2. Type the plain http://yourdomain.com address.
  3. Confirm the browser jumps to https:// automatically.
  4. Test a few internal pages too.

If the redirect loops endlessly, your application may already be forcing HTTPS on its own. Remove one of the duplicate redirects so they do not conflict.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.