Enforcing HTTPS in cPanel¶
If an SSL certificate is already active, you can force automatic redirection from:
to:
This ensures that the website is always opened over a secure HTTPS connection.
1. Where to enable HTTPS redirection¶
After logging in to cPanel, go to:
Domains
Then find your domain in the list.
Example:
Next to the domain, find:
Force HTTPS Redirect
2. Enable Force HTTPS Redirect¶
If the option is disabled, switch it to:
On
Done.
From now on, opening:
should automatically redirect to:
3. Verify that it works¶
After enabling the redirect, open in your browser:
If everything works correctly, the address should automatically change to:
Also check:
if you use the www version.
4. Force HTTPS Redirect is unavailable¶
If you cannot enable this option, first check whether the domain has a working SSL certificate.
Go to:
Security → SSL/TLS Status
and check whether the domain has a valid certificate.
If there is no certificate, first run AutoSSL or install your own certificate.
5. The website stopped working after enabling HTTPS¶
If the website shows an error after enabling the redirect:
- disable Force HTTPS Redirect,
- check whether the SSL certificate is valid,
- check whether the application supports HTTPS,
- check the website configuration.
The problem may be caused by:
- an invalid certificate,
- incorrect URLs in the application,
- an outdated WordPress configuration,
- an incorrect
.htaccessfile.
6. Mixed Content¶
Sometimes the website opens over HTTPS, but the browser still shows a warning.
This may mean that some resources are still being loaded over HTTP.
Example:
instead of:
This may affect:
- images,
- CSS,
- JavaScript,
- fonts.
This issue is called:
Mixed Content
In that case, update the resource URLs in the website or application.
7. WordPress¶
If you use WordPress, after enabling HTTPS it is worth checking:
They should use:
instead of:
If WordPress still generates old HTTP addresses, redirect errors or Mixed Content warnings may occur.
8. Simplest procedure¶
To enforce HTTPS:
- Log in to cPanel.
- Go to:
Domains
- Find your domain.
- Enable:
Force HTTPS Redirect
- Open:
- Check whether it redirects to:
Done.
If the option does not work or causes an error, first check the certificate in Security → SSL/TLS Status.