Skip to content

Redirect Checker guide

Tool guide. Updated .

How the Redirect Checker follows HTTP, HTTPS and www variants to the final page, what 301, 302, 307 and 308 mean, and how to fix loops and long chains.

What redirects do

A redirect is a response with a 3xx status code and a Location header telling the client where to go instead. Browsers follow it automatically, as do search engine crawlers and most HTTP libraries. Sites use redirects to move visitors from HTTP to HTTPS, to pick one host name (with or without www), and to keep old URLs working after a redesign.

Every hop costs a round trip, and each extra hop is another place where something can go wrong. A clean setup reaches the final page in one or two redirects. The Redirect Checker shows the whole chain so you can see exactly what visitors and crawlers go through.

A typical healthy redirect chainThe request starts at http://example.com, is redirected to https://example.com, then to https://www.example.com, which answers 200.http://example.com/301 → https://example.com/ (move to HTTPS onthe same host)https://example.com/301 → https://www.example.com/ (pick thepreferred host)https://www.example.com/200 OK: the final page
The request starts at http://example.com, is redirected to https://example.com, then to https://www.example.com, which answers 200.

How to use the Redirect Checker

  1. Open the Redirect Checker and enter a domain, for example example.com.
  2. XGM requests http://example.com, https://example.com, http://www.example.com and https://www.example.com from its server and follows each chain for up to ten hops, including meta refresh tags.
  3. The table shows where each of the four ends; the raw chains list every hop with its status code, Location and response time.
  4. Read the findings: variants that end at different URLs, hops that could be skipped, meta refresh, temporary redirects, loops, downgrades and errors.
  5. Fix the configuration and run the check again from the permalink. The Full report tab also compares the http:// and https:// final URLs and reads the canonical tag.

Every redirect target is checked against the same rules as the starting URL, so a chain that points into a private network is stopped. That protects XGM, and it also means a redirect to an internal host shows up as refused rather than followed.

Redirect status codes

3xx codes used for redirects
CodeMeaningMethod on follow-upUse for
301 Moved PermanentlyPermanentClients may change POST to GETPermanent moves of pages and hosts
308 Permanent RedirectPermanentMethod and body preservedPermanent moves of APIs and form targets
302 FoundTemporaryClients may change POST to GETShort-term redirects
307 Temporary RedirectTemporaryMethod and body preservedTemporary redirects of APIs
303 See OtherGo to another resource with GETAlways GETAfter a form submission

Search engines treat permanent redirects as a signal to index the target URL instead of the old one. A temporary redirect keeps the old URL as the canonical one, which is rarely what you want for HTTP-to-HTTPS or domain changes. The checker notes temporary redirects so you can decide whether they are intentional.

What the findings mean

Redirect Checker findings
FindingSeverityAction
No redirectsPassedThe URL answers directly. For http:// this means no HTTPS redirect exists; see the final-URL finding.
All reachable variants end at …PassedThe four entry URLs reach one final URL without loops or meta refresh.
The variants end at n different URLsWarningPick one final URL and 301-redirect the others to it.
… takes n hops to reach …Info or warningTwo hops is a note, three or more a warning; redirect straight to the final URL. A first hop from http:// to https:// on the same host is never counted as unneeded.
… redirects with a meta refreshWarningAnswer with an HTTP 301 instead of an HTML page that moves on.
… does not redirect to https://example.com firstInfoNeeded only for HSTS preload of the bare domain.
Temporary redirects (302/307)InfoUse 301 or 308 if the move is permanent.
Redirect loop detectedCriticalThe chain visits the same URL twice; fix conflicting rules.
More than 10 redirectsCriticalToo many hops; simplify the rules.
A hop redirects from https:// to http://CriticalNever downgrade; send all redirects to HTTPS URLs.
The site ends on plain HTTPWarningAdd an HTTP-to-HTTPS redirect on the server.
… ends in HTTP 4xx/5xxCriticalThe chain ends in an error page; fix the target.
www.example.com does not resolveInfoFine if unused; otherwise add DNS and a redirect.

Fixing common problems

Collapsing a long chain

Chains grow when rules are added independently: the CDN forces HTTPS, the web server adds www, the application adds a trailing slash and a language prefix. Each rule redirects once, and together they create four hops. Point each old variant straight at the final URL.

nginx: HTTPS and www in one hop per variant
server {
    listen 80;
    server_name example.com www.example.com;
    return 301 https://www.example.com$request_uri;
}

server {
    listen 443 ssl;
    server_name example.com;
    return 301 https://www.example.com$request_uri;
}

HSTS preload is the exception

If you want to preload HSTS, the first hop must stay on the same host (http://example.com → https://example.com) so the bare domain can send its HSTS header. See the HSTS guide.

Breaking a loop

Loops usually come from two layers disagreeing. A typical case is a CDN connecting to the origin over HTTP while the origin redirects HTTP to HTTPS, and the CDN forwards that redirect back to the visitor. Configure the CDN to use HTTPS to the origin, or make the origin trust the forwarded protocol header from the CDN.

Keeping paths and query strings

Redirects that send every old URL to the home page lose the visitor's context and search rankings. Preserve the path with $request_uri in nginx or %{REQUEST_URI} in Apache, and map changed paths individually.

Test all four variants

Visitors can arrive at four versions of the same site: http://example.com, http://www.example.com, https://example.com and https://www.example.com. All four should end at the same final URL in as few hops as possible. Checking only the one you type yourself misses the others, which are exactly the ones old links use.

Expected results when www is the preferred host
StartExpected chain
http://example.com301 → https://example.com → 301 → https://www.example.com (or directly to www)
http://www.example.com301 → https://www.example.com
https://example.com301 → https://www.example.com
https://www.example.com200

Run the checker with example.com and with www.example.com to cover the two HTTP starting points, and use the HTTP Headers Checker for the HTTPS variants. A mismatch, such as www redirecting to the bare domain while the bare domain redirects to www, is the classic loop.

Redirects and search engines

Crawlers follow redirects but, like browsers, prefer short chains. Each extra hop delays discovery and can cause crawlers to give up on very long chains. After a site move, keep permanent redirects in place for a long time, because links from other sites and bookmarks keep pointing at old URLs for years.

  • Link internally to the final URLs, not to URLs that redirect.
  • Make the canonical link element on each page match the final URL.
  • Update sitemaps to list only final URLs.
  • Use the domain migration checklist when moving a whole domain.

FAQ

Why does the checker start at http://?

So the HTTP-to-HTTPS redirect is part of the result. Many visitors still arrive through old links or typed addresses without a scheme.

Is a 301 or a 308 better?

For web pages both work. 308 guarantees the request method is kept, which matters for APIs and forms that POST; 301 is the traditional choice for page moves.

How many redirects are too many?

One hop, or two when the first moves from http:// to https:// on the same host, is ideal. The checker warns at three and stops after ten, which is roughly where clients and crawlers give up.

Do redirects hurt SEO?

Permanent redirects pass most signals to the target. Long chains, temporary redirects for permanent moves and redirects to irrelevant pages are what cause problems.

Can the checker see JavaScript or meta refresh redirects?

Meta refresh tags, yes: the first 64 KB of an HTML page are read and a refresh with a URL is followed as a hop and flagged. JavaScript redirects, no; they need a browser that runs the page.

Why is a redirect target refused?

Targets are checked against the same public-address rules as the starting URL. A chain pointing to a private or internal address is stopped.

Should HTTPS pages ever redirect to HTTP?

No. A downgrade exposes the visitor on the second request and conflicts with HSTS. The checker marks it as critical.

Sources