.htaccess Validator
Checks .htaccess files for unknown directives, unclosed blocks, and bad rewrite rules.
Generate Apache .htaccess rules for page redirects, HTTPS, www or non-www, trailing slashes, and domain moves. The rules are combined so each visitor gets a single redirect, not a chain.
.htaccess file in your site's root folder.All rules use mod_rewrite and start with RewriteEngine On. Using one module for everything avoids the ordering surprises you get when mixing Redirect and RewriteRule.
^old-page\.html/?$, with dots and other special characters escaped. The /? also catches the same URL with a trailing slash. A relative target is turned into a full URL on your preferred host, so the visitor lands on the final address in one step.[OR] conditions, so http://www.example.com goes straight to https://example.com.!-d) so folder URLs keep working.[R=301,L]: redirect with the chosen code, then stop processing.Domain example.com, force HTTPS, remove www, and redirect /old-page.html to /new-page:
RewriteEngine On
# Page redirects
RewriteRule ^old-page\.html/?$ https://example.com/new-page [R=301,L]
# HTTPS and non-www in one redirect
RewriteCond %{HTTPS} off [OR]
RewriteCond %{HTTP_HOST} ^www\. [NC]
RewriteRule ^ https://example.com%{REQUEST_URI} [R=301,L]
| Code | Meaning | Use it when |
|---|---|---|
| 301 | Moved permanently | A page or site has moved for good. Search engines move rankings to the new URL. |
| 302 | Found (temporary) | The move is temporary, such as a sale page or maintenance. |
| 307 | Temporary redirect | Like 302, but the browser must keep the method and body (a POST stays a POST). |
| 308 | Permanent redirect | Like 301, but the method and body are kept. |
mod_rewrite and AllowOverride enabled. Nginx, IIS, and most Node hosts ignore .htaccess.%{HTTPS} is always off and the HTTPS rule loops. Check %{HTTP:X-Forwarded-Proto} instead, or let the CDN force HTTPS.RewriteCond %{QUERY_STRING} line.In your site's document root, the folder that holds index.php or index.html. Put these rules above any rules your CMS already has, such as the WordPress block.
Check that mod_rewrite is enabled and that the server allows overrides. Also clear your browser cache, because an old 301 may be cached.
A chain is several redirects in a row, such as http → https → non-www → new page. Each hop adds delay, and search engines may stop following long chains. These rules send visitors to the final URL in one step.
Use 301 for permanent moves. It tells search engines to index the new URL and pass the old page's ranking signals to it.
Often used together with the .htaccess Redirect Generator.
Checks .htaccess files for unknown directives, unclosed blocks, and bad rewrite rules.
Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.
Creates robots.txt rules for search and AI crawlers and tests URLs against them.