.htaccess Generator
Build an Apache .htaccess file: force HTTPS and www or non-www, move a domain, add 301 redirects, gzip, caching, error pages and hotlink protection, then trace a test URL through every redirect.
How to Use
- Tick the blocks you need — Force HTTPS, a domain move, directory listing, a 404 page, gzip, caching, .ht protection, UTF-8 — and choose a www rule.
- Fill in the old and new domains or a from-path and to-URL for redirects. A block is only written once its fields are complete; problems are explained under the buttons.
- Type a Test URL. The panel on the right shows every redirect that request would go through and where it ends up.
- Read Show Work for the lines each block produced, why, and which Apache modules they need.
- Press Copy or Download, upload the file to your site’s root folder (next to index.html or index.php) and test the URLs you changed.
Worked Example
Force HTTPS and Force www. The file is 5 directive lines: RewriteEngine On, then a condition and a rule for each. A request for http://example.com/blog?p=2 matches the first rule (%{HTTPS} is off) and gets a 301 to https://example.com/blog?p=2. The browser asks again; now the second rule matches (the host does not start with www.) and sends it to https://www.example.com/blog?p=2. That is 2 redirects, and the query string ?p=2 survives both, because mod_rewrite passes it on unless the target contains its own ?.
A domain move. Old domain oldsite.com, new https://newsite.com. The condition ^(www\.)?oldsite\.com$ matches www.oldsite.com; in an .htaccess file the path that ^(.*)$ sees is about, without the leading slash, so https://newsite.com/$1 becomes https://newsite.com/about — 1 redirect.
The common mistake: writing RewriteRule ^/old-page$ /new-page [R=301,L] in .htaccess. It never matches. In a per-directory file Apache removes the folder’s prefix before matching, and the removed prefix always ends with a slash, so the pattern sees old-page. Write ^old-page$. The simpler Redirect 301 /old-page https://example.com/new-page does take the leading slash, and it also moves /old-page/photos to /new-page/photos while leaving /old-pages alone, because it matches whole path segments.
Show Work
Directive Reference
Where .htaccess Came From
The name means “hypertext access”. The NCSA HTTPd server of the early 1990s let a folder carry its own access-control file, so people without access to the server’s main configuration could password-protect their pages. Apache, first released in 1995, grew out of a set of patches to NCSA HTTPd and kept the file, and it gradually learned to hold almost any directive, not just access rules.
Ralf S. Engelschall wrote mod_rewrite in 1996; its regex-driven rules are why most redirects in .htaccess files look the way they do. The convenience has a price: Apache looks for an .htaccess in every folder along a request’s path on every request, so its documentation recommends putting rules in the main configuration when you can. Since version 2.3.9 the default AllowOverride None ignores .htaccess files entirely until a server administrator turns them on, which shared hosts do.
About This Tool
This generator writes standard Apache blocks for the jobs people most often need: HTTPS, one canonical hostname, a domain move, single-page redirects, directory listings, a custom 404, compression, browser caching, protecting .ht files, hotlink blocking and UTF-8. RewriteEngine On is written once, however many rewrite rules you choose.
What sets it apart is the redirect trace: type any URL and it is run through the rules exactly as Apache would, one request at a time, so you can see a two-hop chain or a loop before you upload. Show Work explains every line and lists the modules the file depends on. Everything runs in your browser; nothing is uploaded.
It is for site owners on shared hosting, developers moving a site to HTTPS or a new domain, and anyone who would rather not debug mod_rewrite by trial and error. Keep a copy of your current file and test changes on a staging site first.
Related tools: robots.txt Generator, HTTP Status Codes, and .gitignore Generator.
Frequently Asked Questions
What is an .htaccess file and where does it go?
It is a per-directory configuration file for the Apache web server (and LiteSpeed, which reads the same syntax). Apache checks for it on every request and applies its redirects, access rules, compression and caching to that folder and everything below it. Put site-wide rules in the document root, often called public_html or www. It only works if the server allows it with AllowOverride; since Apache 2.3.9 the default is None, so hosts have to switch it on.
What is the difference between a 301 and a 302 redirect?
A 301 says the page has moved permanently: browsers may cache it and search engines move rankings to the new URL. A 302 says the move is temporary and the old URL should keep being used. HTTPS upgrades, domain moves and renamed pages should be 301, which is what every rule here writes (R=301, Redirect 301). Because browsers cache a 301, test with a private window when you change one.
Why do Force HTTPS and Force www give two redirects?
They are separate rules and Apache stops at the first one that matches. http://example.com/ first becomes https://example.com/; the browser asks again and only then is it sent to https://www.example.com/. Visitors still arrive, but each hop is an extra round trip. The Test URL trace shows the chain; a hand-written rule that checks both conditions can do it in one step.
Which Apache modules do these blocks need?
The HTTPS, www, domain-move and hotlink rules need mod_rewrite. Redirect 301 uses mod_alias, compression mod_deflate (with mod_filter for AddOutputFilterByType), caching mod_expires and the download header mod_headers. Blocks wrapped in <IfModule> are skipped quietly if the module is missing; the others cause a 500 error, so check with your host. Show Work lists the modules your file needs.
Does .htaccess work on Nginx?
No. Nginx ignores .htaccess files completely. The same results come from directives in nginx.conf: return 301 https://$host$request_uri; for HTTPS, gzip on; for compression and expires 1y; for caching, applied when the server reloads rather than read on every request.
How do I use the .htaccess Generator?
Just pick your options. The answer shows up right away — there is no button to press. Change anything and it updates by itself.
Does it cost anything or need an account?
No. The tool is completely free, there is no account to create, and it keeps working offline after the page first loads.
Is anything I type uploaded?
No. The tool works entirely on your device, so the values you enter never leave your browser.
Common Use Cases
Force HTTPS site-wide
Two lines send every http:// request to the same address on https:// with a 301, so search engines index one version of each page.
Pick one hostname
Force www or non-www so example.com and www.example.com do not split links and analytics between two copies of the site.
Move to a new domain
oldsite.com/about and www.oldsite.com/about both go to https://newsite.com/about in one hop, with the query string kept.
Rename a section
Redirect 301 /old-page https://example.com/new-page also moves /old-page/photos to /new-page/photos, but not /old-pages.
Speed up repeat visits
Gzip shrinks HTML, CSS and JS, and a one-year expiry on images and fonts lets returning visitors load them from cache.
Harden a folder
Stop file listings with Options -Indexes, refuse .htaccess and .htpasswd downloads, and block other sites from embedding your images.
Last updated: