LEARN · HTTPS-REDIRECT
Redirect HTTP to HTTPS
Why your site should always redirect http:// to https:// and how to avoid mixed content.
WHAT IT IS
Even with HTTPS, someone may type your address without "https" or follow an old link. A permanent (301) redirect always takes them to the secure version. Mixed content is when a secure page loads resources over http://.
WHY IT MATTERS
Without a redirect, part of your traffic travels unencrypted. Mixed content makes the browser block scripts or images, or show warnings.
COMMON MISTAKES
- Redirecting with 302 (temporary) instead of 301.
- Long chains: http → http://www → https://www → https://.
- Images or scripts with absolute http:// URLs in the HTML or CMS.
EXAMPLE
server {
listen 80;
server_name example.com www.example.com;
return 301 https://example.com$request_uri;
}HOW WE CHECK IT
- HTTP_TO_HTTPS v1.0.0 — That the http:// version of the site redirects to https://.
- HTTP_REDIRECT_CHAIN v1.0.0 — Number of redirects until the final page.
- HTTP_MIXED_CONTENT v1.0.0 — Whether an HTTPS page loads resources (scripts, styles, images, iframes) over http://.