REDIRECT CHAIN

HTTP Redirect Checker

Follow the redirect chain from the plain HTTP address to the final HTTPS page and check each hop for downgrades, loops and wasted steps.

Run Redirect chain

The domain (or a subdomain). The check stays within that name and its www counterpart, like the full assessment.

No sign-up required. Public hosts and addresses only; results show what was observed, nothing is simulated.

What the redirect checker traces

A redirect tells the browser to request a different URL. Sites use them to move visitors from HTTP to HTTPS, from the apex to www or the reverse, and from old paths to new ones. This tool starts with a plain request to port 80 of the host, which is where an unprepared visitor typing the address arrives, and shows the status and Location it returns. It then follows the HTTPS chain from the site, listing each hop's URL, status code, Location header and address.

Following stays within the domain's apex and www names, makes at most four HTTPS requests, and validates every hop before it is contacted.

How to read the chain

The headline tells you where the chain ends and whether the redirect behaviour is sound.

  • 301 or 308: permanent redirects; 308 keeps the request method.
  • 302 or 307: temporary redirects; fine for short-term moves, but a permanent HTTP to HTTPS rule is normally permanent.
  • HTTP to HTTPS pass: port 80 answers with a redirect whose target uses https.
  • Redirect to plain HTTP: reported as an improvement of medium severity because the chain steps back to an unencrypted URL.
  • HTTP served without redirect: content is returned over HTTP, so visitors who type the address stay unencrypted.
  • Port 80 closed: informational. Browsers that try HTTP first will fail instead of being upgraded.
  • Loop: a Location points to a URL already requested earlier in the chain.

Why redirect design matters

Each extra hop adds a round trip, so a chain like http to https to www to a path costs visitors time. A single hop from the HTTP address straight to the final HTTPS URL is the cleanest. For security, the first request is the vulnerable moment: an unencrypted request can be tampered with before the redirect arrives. Redirecting is a basic protection, and HSTS then reduces repeat exposure by telling browsers to skip the HTTP step. The two work together; neither replaces the other.

Common problems

  • Loops between apex and www when both redirect to each other, often because the CDN and the origin disagree about the canonical host.
  • Redirect to HTTP caused by a back-end that builds absolute URLs from the internal scheme behind a TLS-terminating proxy.
  • Long chains after several migrations stacked rules.
  • Off-site redirects: the Location moves to another domain; the tool reports it without contacting it.
  • Temporary codes used permanently, which can slow how quickly clients and search engines adopt the new address.

How to fix redirects safely

Prerequisites: know the canonical hostname you want and where redirect rules live: web server, application, CDN or load balancer. Risk: a wrong rule can lock visitors into a loop. Rollback: keep the previous rule set and test with a command-line client before and after.

  1. Decide the canonical URL form, for example https and the www host.
  2. Implement one rule at one layer that sends HTTP and non-canonical hosts directly to it with a permanent status.
  3. Remove duplicate rules at other layers so they do not fight.
  4. Test using curl -sIL http://example.com/ and read each Location.
  5. Re-run this checker and confirm a short chain, https at every step and no loop.

Limits

Redirects done in HTML meta refresh tags or by JavaScript are invisible because no page is rendered. Only the site root is requested, so rules for other paths are not shown. Targets outside the apex and www boundary or on other ports are reported but not contacted, so a chain that continues elsewhere is cut short. Some edge networks drop automated requests; the tool reports that without drawing a conclusion about your configuration.

Frequently asked questions

Should I use 301 or 302?

Use a permanent code such as 301 or 308 for a permanent move, including HTTP to HTTPS. Temporary codes suit short-term moves.

Why does the checker stop after a few hops?

It makes at most four HTTPS requests and stays within the apex and www names, reporting where the chain would continue.

Is closing port 80 acceptable?

It works for HTTPS-only audiences, but visitors typing the plain address will see an error instead of an upgrade.

Does a redirect from HTTP replace HSTS?

No. The redirect fixes the first visit; HSTS makes browsers skip HTTP on later visits. Use both.

What causes a redirect loop?

Two rules, often at different layers, each sending visitors to the other's canonical form.

Are JavaScript redirects shown?

No. Only HTTP-level redirects are traced.

Scope of this tool

  • Only the domain's apex and www host are contacted over HTTPS (and port 80 where stated); redirects to any other host are reported, never followed.
  • Spectra identifies itself honestly and does not imitate a browser, so sites that block automated clients may not show their real headers.
  • A single request path (/) is examined from this scanner's network position; other pages, other nodes of a load-balanced site and other regions may differ.

Written by DNS Tools editorial · Last updated 2026-10-09