.htaccess Generator for Apache

Tick the rules you need and get a commented .htaccess for Apache 2.4 — HTTPS and www redirects, 301s, compression, caching, security headers, IP blocking and SPA routing.

Loading tool…

About the .htaccess Generator

Apache reads .htaccess on every request in each directory, so rules apply without a server restart. They only work if the virtual host allows it with AllowOverride All (or the specific groups FileInfo, Options, Indexes, AuthConfig). Redirects use mod_rewrite; each block is wrapped in <IfModule> so a missing module does not cause a 500 error.

HTTPS and www canonicalisation are combined into one rule so visitors get a single 301 hop instead of two. Behind a load balancer or Cloudflare, Apache sees plain HTTP, so enable the proxy option to test X-Forwarded-Proto and avoid redirect loops. Custom redirects are matched exactly with escaped patterns, so /old.html does not also match /oldXhtml.

Caching uses mod_expires: HTML revalidates on every visit while images, fonts, CSS and JS can be cached for up to a year if your file names change on deploy. Enable HSTS only after HTTPS works on every subdomain — browsers remember it for the whole max-age. IP blocks use Apache 2.4 Require not ip syntax.

How to use it

  1. Enter your domain and choose HTTPS and www behaviour.
  2. List any 301 redirects, one per line: old path, then new path or URL.
  3. Tick compression, caching, security headers and access rules.
  4. Copy or download the file and upload it as .htaccess to your site root.
  5. Test redirects with curl -I before relying on them.

Frequently asked questions

Why does my .htaccess cause a redirect loop?
Usually HTTPS is terminated at a proxy or CDN, so %{HTTPS} is always off. Enable the proxy option to check X-Forwarded-Proto instead.
Why are my .htaccess rules ignored?
The server must allow overrides (AllowOverride All in the virtual host), mod_rewrite must be enabled (a2enmod rewrite), and the file must be named exactly .htaccess.
Does nginx support .htaccess?
No. nginx has no per-directory config files; the same rules must be written as return/rewrite and add_header directives in the server block.
Should I use 301 or 302 redirects?
Use 301 (or 308) for permanent moves so search engines transfer ranking. Use 302/307 only for temporary changes; browsers cache 301s aggressively, so test first.

Related tools