What is .htaccess?
.htaccess is a small settings file for a website on an Apache server. The server reads it before showing a page. You can add rules to it, such as "send everyone to https". A redirect is a rule that moves a visitor from one address to another.
Before you start
- Install an SSL certificate and check that
https://yourdomain.comworks. - Take a backup of the .htaccess file. A mistake can break your site.
Steps
- Log in to cPanel and open File Manager.
- Go to the
public_htmlfolder. - Click Settings at the top right. Tick Show Hidden Files (dotfiles) and click Save.
- Right-click
.htaccessand choose Download to keep a safe copy. If the file does not exist, click + File and create one named.htaccess. - Right-click it and choose Edit.
- Add these lines at the very top:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]
Line one turns on the rewrite feature. Line two checks if the visit is not secure. Line three sends it to the https address. The 301 tells browsers and search engines the move is permanent.
- Click Save Changes.
- Open
http://yourdomain.comin a new window. It should jump to https.
Warning: if you see a 500 error, you made a typing mistake. Upload your backup copy to undo it.
WordPress sites
Put the lines above the # BEGIN WordPress block. Also set both addresses to https:// in Settings then General.
Redirect loops
If you see "too many redirects", another rule or a service like Cloudflare may also redirect. Keep only one place that forces https.
Quick recap
- Install SSL first.
- Back up .htaccess.
- Add the three rewrite lines at the top and save.
- Test the http address.
- Keep only one redirect rule.