Security · NinjaOps Guides
HTTP to HTTPS: The Redirect Chain Google Expects
Every http:// request must 301 to https:// on the same URL — one hop, no detours. Broken redirect chains split crawl signals and leak users.
How to fix it
- 301 http:// to https:// at the server/edge level, not with JS.
- Redirect to the equivalent URL, not the homepage.
- Chain length: one hop. Two hops is a bug.
- After adding HSTS, browsers enforce the redirect for you.
Diagnose this exact issue on your site — free
The 100-Point Affiliate Site Grader runs this check (and 40+ more) on your live site in ~10 seconds. No signup.
Want it fixed for you?
The Zero-Overhead Affiliate Playbook walks through every gap in this guide in 14 days on a $0 stack. Join the launch list →
More Security fixes: