Walkthrough · Beginner · 10 minutes
How to Force HTTPS on Your Site
How to every arrival sent to the encrypted address, with nobody left behind on http, without the guessing — the steps in order, the snag ahead of time, and the tip our support team repeats daily.
The short answer
The job: every arrival sent to the encrypted address, with nobody left behind on http. Time to set aside: 10 minutes. Skill needed: beginner.
Below are the precise steps, the classic stumble, and one tip from the support desk. Wherever the platform already does a step for you, the guide says so rather than handing you a machine's chores.
By the Hosting & Domains team · Reviewed 18 August 2026
Beginner
Experience required
5
Stages, start to finish
Free
Support included
Proven
On the platform itself
No prior knowledge assumed — a hosting account, a browser and 10 minutes of attention is the whole entry requirement. Every instruction runs on our platform exactly as printed, and carries over to any standard cPanel host.
First rule: read the snag section before you start, not afterwards. It was distilled from the tickets of everyone who tried the other order.
The whole job in one view
Set out end to end, the route is: check https works before you force it, use the built-in toggle, or write the rule into .htaccess, correct the wordpress address settings and clear out any lingering http references.
Every stage is a few minutes of unhurried clicking — the total depends mostly on how well you already know the control panel. The detailed instructions are further down; read the whole path once before you begin.
One caution before you click anything
Redirect loops from duplicated rules. The panel toggle, a plugin and an .htaccess directive can end up passing requests between themselves indefinitely. Pick one mechanism, set it up properly, and switch the others off.
It earns a section of its own because it is no obscure edge case — it is the single commonest reason this task reaches a support queue. Knowing it in advance turns the whole job from risky into routine.
A habit worth borrowing
After a few clean weeks on https, add an HSTS header so browsers give up on http entirely. One line buys a permanent improvement, though keep the duration short until you are certain nothing is uncovered.
Habits this small are what separate the people who find hosting effortless from the people who find it draining. The same tools on both sides — a different way of working.
The steps already done before you arrive
Some steps in this guide exist only because hosting traditionally forced them on you. Here the SSL issues itself, the copy is taken daily without being asked, and one-click installers remove the manual setup. What is left is the part that was always genuinely yours.
Should a step still misfire, support answers at any hour with an actual fix rather than a knowledge-base link and a shrug. Half the guides on this site began as repeat patterns in our ticket queue.

The hosting these steps were tested on
Tutorials written against imaginary hosting go stale fast. Ours are written against the real thing: the same panel, installer and defaults waiting in your account.
Order an annual plan and the first year of the name's registration is on us.
- Every step checked exactly as published
- The snag named before it arrives
- The dull steps taken out of your way
- People reachable at any hour you stall
Why Hosting & Domains
Standard on every plan
Honest about how big it is
Every arrival sent to the encrypted address, with nobody left behind on http is a beginner-level job — set aside 10 minutes, with the platform-absorbed steps marked.
The snag, flagged up front
The classic error for this particular task is named before step one, which is how 10 minutes stays 10 minutes.
Jargon never charges you
Every term is defined on the spot or linked to the jargon buster — nothing assumes prior knowledge.
Works exactly as printed
Every step is proven on the platform we run — none of the 'your host may vary' hedging.
5 steps, nothing padded
Each stage is a few minutes of steady clicking, and the fiddly moments are labelled fiddly.
Taken from real tickets
These guides came out of the support queue, so every snag flagged is one people genuinely hit.
Quick Start
Order placed to site online
- 1
Check https works before you force it
Herding visitors onto a broken https page only beats no redirect in theory. Open the https address yourself and confirm it renders cleanly before anybody is pushed there.
- 2
Use the built-in toggle
The Domains page in cPanel offers Force HTTPS for each domain. It is the tidy, configuration-level redirect and it covers the entire site in one action.
- 3
Or write the rule into .htaccess
The traditional RewriteRule sending http to https gets the same result explicitly. Choose it when you want the rule sitting alongside the site's own code and history.
- 4
Correct the WordPress address settings
Settings → General has to read https. When WordPress prints http links onto an https site, every click drags an avoidable extra redirect along behind it.
- 5
Clear out any lingering http references
Run a database search-replace for embedded http URLs, images most of all. The padlock should hold on every page of the site rather than most of them.
Built In
Fitted to every plan
- WordPress Toolkit, with the updates seen to for you
- LiteSpeed caching in the server itself rather than bolted on by plugin
- Mailboxes that answer at the name you hold
- WebP image optimisation built in, at no extra charge
- Free SSL on every plan, reissued before the old one lapses
- People on the support desk every hour of every day
- A daily copy, with restores you run yourself from the panel
- The name's first year included when you order annually
- No set-up charge at any point, and no joining fee
- NVMe SSD storage on every tier, not only the dear ones
Frequently Asked
The questions that come up most
Does forcing HTTPS put rankings at risk?
Quite the reverse. https counts as a ranking signal, and 301 redirects pass the accumulated value straight over. Within weeks Search Console starts treating the https URLs as canonical, which is the migration completing rather than failing.
I am getting 'too many redirects' — how do I stop it?
Two mechanisms are wrestling: usually a plugin redirect against the panel or .htaccess rule, or an upstream proxy sending traffic back. Switch every redirect source off but one, clear the caches, and the loop dies.
Can I choose the PHP version myself?
Yes — PHP is set per site from the control panel, so a legacy application and a current one can run side by side in one account. Extensions and per-site tuning are on the same screen, and none of it goes near a support ticket.
How do payments and auto-renewal work?
You pay by credit or debit card through a secure checkout, and renewals bill at the same rate as the original order. Every invoice sits in your client area, and auto-renewal switches off with a toggle in the account — no telephone call needed.
Keep reading
How to Free Up Mailbox Storage
Reclaim space before senders start collecting bounce messages — beginner level, about 20 minutes.
How to Set Up DKIM Signing
Cryptographically sign outgoing mail so spoofing and tampering both surface — intermediate level, about 10 minutes.
Brute-Force Attack (Glossary)
The full definition, along with the practical consequence nobody bothers to mention.
Email Hosting
Proper mailboxes at your own name, for one flat rate.
VPS Hosting
KVM virtual servers — root access, DDoS filtering, one flat monthly figure.
Changing hosts? Run through our checklist first.
A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.
The name is waiting.
Free SSL, a free migration, renewals billed at the original rate, and people on support around the clock. That is the whole of it.
View Email Hosting plans