How to force my website to use HTTPS
Before you start: check the certificate works
Open https://yourdomain.co.za (with the s) in a private browser window. You need a padlock and no warning. If you see "Not secure" or a certificate error, fix that first, or forcing HTTPS will lock every visitor out of the site. See Why does my website say "Not secure"?
Free certificates are issued automatically once your domain's DNS points to your Webway server. If you just moved or pointed the domain, allow a few hours.
Option 1: One-click in cPanel
- Log in to cPanel and open Domains.
- Find the domain and switch Force HTTPS Redirect on.
Done. Repeat for subdomains and addon domains.
DirectAdmin: open Account Manager → Domains, click the domain, tick Force SSL with https redirect and save.
Option 2: Add a rule to .htaccess (cPanel and DirectAdmin)
This works on both panels. cPanel's Apache and DirectAdmin's OpenLiteSpeed both read .htaccess rewrite rules.
- Open File Manager and go to the folder your site serves from (
public_htmlfor the main domain). - If you can't see
.htaccess, click Settings and tick Show hidden files. - Right-click
.htaccessand choose Edit. If it doesn't exist, create it. - Add these lines at the top of the file, above anything else:
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
- Save.
To also force www (or remove it), use this instead, replacing the domain:
RewriteEngine On
RewriteCond %{HTTPS} !=on [OR]
RewriteCond %{HTTP_HOST} !^www\.example\.co\.za$ [NC]
RewriteRule ^ https://www.example.co.za%{REQUEST_URI} [L,R=301]
Swap the www. version for the bare domain in both places if you prefer example.co.za without www.
On WordPress, place the rule above the # BEGIN WordPress block. WordPress rewrites its own block and would otherwise overwrite your rule.
Option 3: WordPress settings
Do this as well as Option 1 or 2, not instead.
- In WordPress, go to Settings → General.
- Change both WordPress Address (URL) and Site Address (URL) to start with
https://. - Save. You'll be logged out; log in again at the https address.
Old pages and images may still link to http:// addresses, which shows a "not fully secure" padlock. Fix with a search-and-replace plugin (for example Better Search Replace), replacing http://example.co.za with https://example.co.za across the database. Take a backup first.
Test
- Open
http://yourdomain.co.za(nos) in a private window. It should land onhttps://with a padlock. - Test a deep link too, such as
http://yourdomain.co.za/contact. - Check an online redirect checker shows a single
301to the https address, not a chain.
Problems
| Problem | Cause | Fix |
|---|---|---|
"Too many redirects" / ERR_TOO_MANY_REDIRECTS |
Cloudflare SSL mode set to Flexible, or a plugin also redirecting | In Cloudflare set SSL/TLS to Full. Disable other HTTPS plugins so only one thing redirects |
500 error after editing .htaccess |
Typo in the rule | Remove the lines you added, or restore from a copy. Check every line matches exactly |
| Still loads on http | Rule below the WordPress block, browser cache, or wrong folder | Move the rule to the top. Test in a private window. Check you edited the .htaccess in the folder that serves the domain |
| Padlock with a warning, "not fully secure" | Mixed content: images or scripts still on http | Option 3, and fix hard-coded http links in the theme |
| Certificate error after forcing | Certificate not valid for this name (for example www missing) |
Wait for the free certificate to include the name, or see Why does my website say "Not secure"? |
Did this answer it?