Every site should load over HTTPS. Browsers mark plain HTTP pages as "Not secure", logins and forms are exposed without it, and ad and analytics scripts expect it. On cPanel hosting the certificate is free and mostly automatic. The part that trips people up is the redirect.
Step 1: make sure a certificate is installed
In cPanel, open SSL/TLS Status. Each address on the account is listed with a padlock: green for a valid certificate, red for none. Tick the ones that are red and press Run AutoSSL. Issuing usually takes a few minutes.
If AutoSSL fails for a name, the page says why. The usual reasons:
- The name does not point at this server. AutoSSL proves you control the domain by fetching a test file from it. If the DNS record for
wwwormailpoints elsewhere, that name fails. Fix the DNS record, or exclude that name from AutoSSL. - Something blocks the test file. The check requests an address under
/.well-known/. A rule in.htaccessthat redirects everything, or password protection on the whole site, can stop it. Exempt that folder. - The domain was added minutes ago. DNS changes need time to spread. Try again in an hour.
Step 2: redirect HTTP to HTTPS
The simple way: open Domains in cPanel and switch on Force HTTPS Redirect for the domain. The switch only becomes available once a valid certificate is in place.
If you prefer to do it by hand, or your cPanel version lacks the switch, add this near the top of .htaccess in public_html:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Use one method, not both.
The redirect loop, and why it happens
If the browser reports "too many redirects" right after you add the rule, the site is almost certainly behind a proxy such as Cloudflare that is set to connect to your server over plain HTTP (Cloudflare calls this mode "Flexible"). The visitor arrives over HTTPS, the proxy fetches the page from your server over HTTP, your server sees an insecure request and redirects, and round it goes.
The right fix is at the proxy: set its SSL mode so it connects to your server over HTTPS and checks the certificate (Cloudflare's "Full (strict)"). Your server already has a valid certificate from Step 1, so this works straight away and the traffic is encrypted the whole way.
Step 3: clean up mixed content
After the redirect, a page can still show a warning if it loads an image or script from an http:// address. Open the browser's developer tools, look at the Console tab, and it lists each insecure item. Change those addresses to https://. In WordPress, also set both site addresses under Settings > General to the https:// version; old addresses saved inside posts can be updated with a search-and-replace tool.
About HSTS
HSTS is a header that tells browsers to refuse plain HTTP for your domain for a set length of time. It is worth having, but add it last, once every address on the domain has loaded over HTTPS without warnings for a week or two. A browser that has seen the header will not let visitors click through a certificate problem, so a mistake is hard to undo. When you are ready:
Header always set Strict-Transport-Security "max-age=31536000"
Renewal
AutoSSL renews certificates by itself before they expire. It can only do that while the domain still points at the server and the check address is reachable, so if you later move DNS or add a blanket redirect, look at SSL/TLS Status again afterwards.
Common questions
Is the free certificate as good as a paid one?
For encryption, yes. A free domain-validated certificate protects the connection exactly as a paid one of the same type does, and browsers show the same padlock. Paid certificates add things such as a warranty or validation of the company's identity, which most small sites do not need.
Should www and non-www both have a certificate?
Yes. A visitor who types the other form of the address meets the certificate check before any redirect can happen, so both names must be covered. AutoSSL includes both as long as both point at the server.
My site is behind Cloudflare. Do I still need AutoSSL on the server?
You do. The proxy's certificate covers the visitor-to-proxy half of the journey. Without a certificate on your server the proxy-to-server half travels unencrypted, and the stricter proxy modes will refuse to connect at all.
How do I check when the certificate expires?
Click the padlock in the browser's address bar and open the certificate details, or look at SSL/TLS Status in cPanel, which lists the expiry date for each name. AutoSSL certificates are short-lived on purpose and are replaced well before that date.