.htaccess Generator
Generate Apache .htaccess rules for HTTPS and www redirects, IP blocking, compression, caching and 301s.
Redirects
Security
Speed and pages
- Back up your current .htaccess first. One wrong line gives an HTTP 500 error for the whole site.
- For Apache and LiteSpeed hosting (cPanel, Hostinger and similar). Nginx, IIS, Vercel and Netlify ignore this file.
- On Cloudflare, set SSL/TLS to Full: Flexible SSL with other HTTPS redirects can loop.
.htaccess
# .htaccess made with ToolKit360 for Apache 2.4 and LiteSpeed.
# Back up your current .htaccess first: one wrong line returns an HTTP 500 error for the whole site.
<IfModule mod_rewrite.c>
RewriteEngine On
# Block hidden files and folders such as .env and .git (but allow .well-known)
RewriteRule (^|/)\.(?!well-known(?:/|$)) - [F]
# Send every visitor to HTTPS in one redirect
# Behind Cloudflare or a load balancer, X-Forwarded-Proto tells whether the visitor used HTTPS.
RewriteCond %{HTTPS} !=on
RewriteCond %{HTTP:X-Forwarded-Proto} !https
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301,NE]
</IfModule>
# Hide folder listings (remove this line if your host shows an error for it)
Options -Indexes
# Compress text files (gzip)
<IfModule mod_deflate.c>
<IfModule mod_filter.c>
AddOutputFilterByType DEFLATE text/html text/plain text/css text/xml
AddOutputFilterByType DEFLATE text/javascript application/javascript application/json
AddOutputFilterByType DEFLATE application/xml application/rss+xml application/manifest+json
AddOutputFilterByType DEFLATE image/svg+xml image/x-icon font/ttf font/otf
</IfModule>
</IfModule>
# Correct types for modern files
<IfModule mod_mime.c>
AddType image/avif .avif
AddType image/webp .webp
AddType image/svg+xml .svg
AddType font/woff2 .woff2
AddType font/woff .woff
AddType application/manifest+json .webmanifest
</IfModule>
# Browser caching: images, CSS and JavaScript for 1 month; pages are always checked
<IfModule mod_expires.c>
ExpiresActive On
ExpiresByType text/html "access plus 0 seconds"
ExpiresByType application/json "access plus 0 seconds"
ExpiresByType application/xml "access plus 0 seconds"
ExpiresByType text/css "access plus 1 month"
ExpiresByType text/javascript "access plus 1 month"
ExpiresByType application/javascript "access plus 1 month"
ExpiresByType image/avif "access plus 1 month"
ExpiresByType image/webp "access plus 1 month"
ExpiresByType image/jpeg "access plus 1 month"
ExpiresByType image/png "access plus 1 month"
ExpiresByType image/gif "access plus 1 month"
ExpiresByType image/svg+xml "access plus 1 month"
ExpiresByType image/x-icon "access plus 1 month"
ExpiresByType image/vnd.microsoft.icon "access plus 1 month"
ExpiresByType video/mp4 "access plus 1 month"
ExpiresByType video/webm "access plus 1 month"
ExpiresByType font/woff2 "access plus 1 year"
ExpiresByType font/woff "access plus 1 year"
ExpiresByType font/ttf "access plus 1 year"
ExpiresByType font/otf "access plus 1 year"
</IfModule>
If your browser saves the file as htaccess or htaccess.txt, rename it to .htaccess before uploading it to your site's root folder.
.htaccess Generator FAQ
How do I redirect HTTP to HTTPS with .htaccess?
Turn on Force HTTPS, copy the file and upload it as .htaccess to your site's root folder. It sends every http:// request to the same page on https:// with one permanent (301) redirect.
Why does my site show a 500 Internal Server Error after editing .htaccess?
Apache rejects the whole file if one line is invalid or uses a module that isn't available. Restore your backup, then add sections one at a time to find the line, and check your host's error log.
How do I block an IP address in .htaccess?
Turn on Block IP addresses and enter one address or range per line, such as 203.0.113.7 or 198.51.100.0/24. The tool writes Require not ip lines inside a RequireAll block, which Apache 2.4 needs; a bare Require not line causes a 500 error.
Should I use www or non-www?
Either works for SEO, as long as one redirects to the other. Pick the one you already use in Google Search Console and links, and use the same choice everywhere.
Why does my site loop with "too many redirects" on Cloudflare?
With Cloudflare's Flexible SSL, your server sees every request as http://, so a simple HTTPS rule redirects forever. Switch Cloudflare to Full SSL; the rules from this tool also check the X-Forwarded-Proto header to avoid the loop.
Is my configuration sent anywhere?
No. The file is built in your browser; your domain, IP addresses and redirects are not uploaded or saved.