HTTP to HTTPS redirect checker
Enter a domain. We trace all four ways people reach it (http and https, with and without www) and check that every one ends at the same HTTPS URL in a single permanent hop, with HSTS in place.
What a correct HTTPS setup looks like
Pick one canonical origin, say https://example.com. Then:
| Visitor types | Should get |
|---|---|
| http://example.com/page | one 301/308 → https://example.com/page |
| http://www.example.com/page | one 301/308 → https://example.com/page |
| https://www.example.com/page | one 301/308 → https://example.com/page |
| https://example.com/page | 200 OK, with a Strict-Transport-Security header |
The path and query string must survive the redirect. A rule that sends every HTTP request to the HTTPS homepage throws away the ranking of every deep page; Google treats mass redirects to the homepage like soft 404s.
The most common imperfection is a two-step chain: http://www. → https://www. → https://. It works, but costs an extra round trip on every visit from an old link. Combine the host and protocol change into one rule.
Why HSTS matters here
After the first HTTPS visit, a Strict-Transport-Security: max-age=31536000; includeSubDomains header tells browsers to rewrite any future http:// link to https:// before sending anything. That removes the insecure first hop entirely for returning visitors and closes the window for downgrade attacks. Only add preload once every subdomain supports HTTPS. HSTS is ignored on plain HTTP responses, so it must be sent from the HTTPS URL.
HTTPS migration checklist for SEO
- Permanent, path-preserving redirects from every HTTP and non-canonical host URL, in one hop.
- Canonical tags, hreflang, internal links, sitemaps and structured data updated to the HTTPS URLs, so you don’t send Google through your own redirects.
- No mixed content: images, scripts and CSS loaded over HTTPS.
- The HTTPS property added in Google Search Console; you do not need the Change of Address tool for a protocol-only move.
- Keep the redirects in place for at least a year, ideally permanently, as Google recommends for site moves.
Questions
Should the HTTP to HTTPS redirect be a 301 or 308?
Either is permanent and Google treats them the same. 308 additionally forbids changing POST to GET, which matters for form endpoints and APIs; for normal pages 301 is the most common choice and works everywhere.
Does moving to HTTPS lose rankings?
Not if every HTTP URL redirects permanently to its exact HTTPS equivalent and internal links, canonicals and sitemaps are updated. Google treats it as a routine site move; brief fluctuations while it recrawls are normal.
www or non-www: which is better?
Neither ranks better. What matters is choosing one and redirecting the other to it consistently, in a single hop, with matching canonical tags.
Why does the http://www variant fail with a DNS error?
The www hostname has no DNS record. That is fine if nobody links to it, but adding the record and redirecting it catches visitors who type www out of habit.
Sources: Google Search Central, “Site moves with URL changes”; RFC 6797 (HTTP Strict Transport Security); RFC 9110 §15.4.