Redirect Checker
Trace redirects from http and https, with and without www, to the final URL and spot loops and extra hops.
Related tools
- HTTP HeadersGrade a site's security headers and cookies, get the header lines to add, and build a Content-Security-Policy that the same check approves.
- TLS CheckerInspect a site's TLS certificate, expiry, issuer and negotiated protocol, with a renewal calendar you can download and a full report.
- SEO MetadataCheck a page's title, description, canonical, robots and Open Graph tags.
- Domain HealthOne check for DNS, email authentication, TLS, security headers and redirects, with a grade per area and a full report.
About this tool
Redirect Checker traces the four addresses that visitors and links actually use - http and https, with and without www - and follows each chain to the page that finally answers. It follows HTTP redirects (301, 302, 303, 307 and 308, RFC 9110 §15.4) and meta refresh tags in HTML, up to 10 hops per address, and stops when a URL repeats, which is how a loop is reported. The final URL that most reachable variants agree on becomes the canonical one, and everything that disagrees with it is listed: variants that end somewhere else, chains that downgrade to plain http, hops that could be skipped, temporary 302 and 307 codes on permanent moves, and addresses that never answer, each with the nginx block that fixes it. It requests only the root path of each name, does not run JavaScript, and therefore does not see redirects performed by scripts, frames or a service worker.
XGM requests http:// and https:// for the domain and its www name at the same time and follows every chain: HTTP redirects (301, 302, 303, 307, 308) and <meta http-equiv="refresh"> tags on HTML pages, up to 10 hops, from its server. It reports loops, errors, meta refreshes, variants that end at different URLs and hops that could be skipped.
Four response headers are kept per hop and shown with it: Cache-Control, X-Robots-Tag, Link and Server.
How to use it
- Open the Redirect Checker tool.
- Enter the public domain, hostname or IP address you want to check.
- Run the check; XGM queries it from its server and lists the findings.
- Copy the output only after checking it looks correct.
- Use related XGM tools if you need a broader diagnostic view.
FAQ
Why does XGM test four addresses when I entered one domain?
A leading www is stripped first, then http, https, http with www and https with www are traced in parallel. Each of the four can be configured separately - a different virtual host, a different certificate, a rule that only exists on one of them - and old links and typed addresses use all four. A site is consistent only when every one of them ends at the same URL.
What counts as a hop that could be skipped?
One redirect to the canonical URL is expected, and a second is accepted when the first is the http to https upgrade on the same host, because the HSTS preload list requires that first hop. Anything beyond that is reported, because each hop is another DNS lookup, connection and round trip before the visitor sees anything. The fix shown is a single 301 straight from the entry URL to the canonical one.
A meta refresh works in every browser. Why is it flagged?
The page has to be downloaded and rendered before the browser moves on, so the visitor sees a flash of the wrong page and the round trip is wasted. Search engines treat it as a weaker signal than an HTTP redirect. XGM follows it like any other hop - it reads only the start of an HTML body to find the tag - and shows the 301 that replaces it.
Does it matter whether I use 301, 302, 307 or 308?
For a permanent move such as http to https or www to apex it does. 301 and 308 are permanent, so search engines transfer ranking signals to the target and browsers may cache the redirect; 302 and 307 are temporary and say the original address is coming back (RFC 9110 §15.4). 307 and 308 additionally guarantee that the method and body are preserved, which 302 and 301 historically do not.
One variant reports a certificate error, but the site opens fine. Why?
Every name that answers on port 443 needs a certificate covering that name, including a name whose only job is to redirect. The www variant is the usual casualty: it is left out of the certificate, so the redirect chain breaks before it can send anyone to the apex. A variant reported as not resolving is the other half of the same problem - the name has no A, AAAA or CNAME record at all.
Read the full Redirect Checker guide