HTTPS Redirect Checker
Test whether the insecure http:// version of a page redirects to https:// in one permanent hop, and whether HTTPS is set up properly behind it.
Fetching and analysing the page…
5 of 5 free checks left today. Create a free account for unlimited checks.
HTTPS Redirect Checker - results and guide
What the HTTPS Redirect Checker checks
- Whether http:// redirects to https:// at all
- Whether the first redirect is permanent (301 or 308) and goes straight to https
- Whether the https version loads with a valid certificate
- The Strict-Transport-Security (HSTS) header and its max-age
- Mixed content: scripts, styles, frames and images still loaded over http
- Forms that submit to an http address
- The full chain of the http:// request
Why redirect HTTP to HTTPS?
HTTPS encrypts the connection between the visitor and the site. Browsers mark plain http pages as "Not secure", Google uses HTTPS as a ranking signal, and several browser features only work on secure pages. Installing a certificate is half of the job. The other half is making sure nobody stays on the insecure version.
If both http:// and https:// answer with a page, you have two copies of the site. Visitors who follow an old link remain unencrypted, and search engines must choose between duplicates. A site-wide permanent redirect solves both.
What a correct setup looks like
Every http URL should answer with a single 301 to the same path on https. The secure response should then send Strict-Transport-Security: max-age=31536000; includeSubDomains. With HSTS the browser remembers to use https for the next year and never asks for the insecure address again, which closes the brief window in which a first request could be intercepted.
The page itself must load everything over https. A script or stylesheet requested over http is blocked by the browser, so parts of the page silently stop working. To check that all four combinations of protocol and www agree, use the WWW Redirect Checker. To be warned before a certificate expires, see SSL monitoring.
How to use the HTTPS Redirect Checker
- Enter the address of the page you want to check. You can leave out
https://. - Press Check HTTPS. The page is fetched from our servers, the way a search engine crawler would fetch it.
- Read the findings from top to bottom: problems first, then warnings. Each one says what to change.
Common problems and how to fix them
http:// does not redirect
Add a rule to the web server. Apache: RewriteCond %{HTTPS} off, then RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]. Nginx: return 301 https://$host$request_uri; in the port 80 server block. Most CDNs have an "Always use HTTPS" switch.
The redirect is a 302
Change the rule to return 301 so the secure URL is treated as the permanent address.
Mixed content warnings
Update hard-coded http:// addresses in templates and content to https://, or use relative URLs. A Content-Security-Policy of upgrade-insecure-requests is a useful stopgap.
Frequently asked questions
Is HTTPS a ranking factor?
What is HSTS?
Should the redirect be 301 or 302?
What is mixed content?
Related SEO tools
- WWW Redirect CheckerTests all four versions of your domain and confirms they end at one address.
- Redirect CheckerFollows every hop of a redirect chain and shows 301s, 302s and loops.
- HTTP Status CheckerThe status code, response headers and protocol a URL returns.
- Canonical URL CheckerFind the canonical tag, see where it points and whether that address loads.
SEO gets visitors to your site. Uptime keeps them there.
Monitor 5 websites free forever and get alerted the moment one goes down. No credit card required.