HTTP to HTTPS Redirect Audit
HTTP-to-HTTPS rules often interact with www normalization, legacy page redirects, and CDN settings to produce 2- and 3-hop chains. This guide tests the four URL variations of each page and identifies where the extra hops come from.
Why HTTPS redirects go wrong
Every HTTP URL should 301 to its HTTPS equivalent. Simple enough. But this redirect interacts with everything else already in place: www normalization, trailing slash rules, page-specific redirects. The result is often 2 or 3 hops where one would do.
The double-redirect problem
What happens:
http://example.com/old-page 301 -> http://example.com/new-page
http://example.com/new-page 301 -> https://example.com/new-page (2 hops)
What should happen:
http://example.com/old-page 301 -> https://example.com/new-page (1 hop) The old redirect was never updated to use HTTPS. So the browser goes HTTP old, HTTP new, HTTPS new. Two hops instead of one.
The triple-redirect problem
3-hop chain:
http://example.com/page 301 -> http://www.example.com/page
http://www.example.com/page 301 -> https://www.example.com/page
https://www.example.com/page 301 -> https://example.com/page
Correct (1 hop):
http://example.com/page 301 -> https://example.com/page Three redirects where one would do. Extremely common. Wastes crawl budget on every affected URL.
The four URL variations
Every page has four versions. All four should resolve to the same final URL:
- http://example.com/page
- https://example.com/page
- http://www.example.com/page
- https://www.example.com/page
One of these is canonical. The other three should each redirect to it in a single hop. If any takes 2+ hops, you have a chain. If any does not redirect at all, you have a canonicalization gap.
Related: For a focused look at www/non-www, see our www vs non-www redirect audit.
How to audit
- Gather your URLs. Export your sitemap or list of important pages. You need the HTTP versions for testing.
- Create all four variations. For each page, generate http/https and www/non-www versions. At minimum, test all HTTP versions.
- Batch check. Paste into the batch checker and run. Each URL's full redirect chain is followed to its final destination.
- Check hop counts. Every URL should reach HTTPS in exactly one hop. Anything with 2+ hops has a chain.
- Verify final URLs are HTTPS. Scan the final URL column. Every destination should start with https://. If any starts with http://, the HTTPS redirect is missing.
Common issues
Old redirects still pointing to HTTP
The most common problem. Redirect rules created before the HTTPS migration still use http:// destinations. Fix: update all existing redirect rules to use https:// in the destination.
CDN and origin disagree
Your CDN forces HTTPS, but your origin also redirects HTTP to HTTPS separately. The CDN terminates SSL, sends the request to the origin as HTTP, the origin redirects to HTTPS, and you get invisible chains. Fix: configure the origin to skip the redirect when receiving requests from the CDN.
HSTS header missing
HTTP Strict Transport Security tells browsers to always use HTTPS, eliminating the redirect for returning visitors. Not a chain issue per se, but adding HSTS improves performance for repeat visitors.
Test from outside your cache. If you recently changed redirect rules, your browser may cache the old behavior. checkredirects.io requests from our servers with no cache, so you see the current live behavior.
How to fix
- Server config (.htaccess, Nginx): Update existing rules to use https:// destinations. Make the HTTP-to-HTTPS rule fire before other redirects.
- CMS redirect plugin: Bulk update destinations from http:// to https://.
- CDN dashboard: Make sure CDN-level redirects and SSL settings do not conflict with your origin.
Verify and monitor
Re-run your batch check to confirm all HTTP URLs now reach HTTPS in a single hop. Then set up redirect monitoring on key pages. Server updates and CDN changes can reintroduce HTTPS redirect issues at any time.
For the full migration picture, see our site migration redirect checklist.
Audit your HTTPS redirects
Batch check the HTTP variations of your URLs and inspect every hop.