Automatic HTTPS

Every hostname you redirect through redirect.pizza gets an SSL certificate, without any action on your side. Your redirects work over both http:// and https://, and visitors never see a certificate warning.

How it works

  1. You point the DNS of your hostname at redirect.pizza.
  2. As soon as we detect the DNS change, we request a certificate for the hostname. This usually takes a few minutes.
  3. We renew the certificate automatically before it expires, for as long as the hostname points at us.

Wildcard hostnames get a wildcard certificate through a DNS challenge. See Wildcard subdomains for the extra DNS record that requires.

Certificate authorities

We issue certificates through Let's Encrypt, with ZeroSSL as a fallback. When one of them is unavailable or rate limited, we switch to the other automatically, so a hiccup at a certificate authority doesn't affect your redirects.

If your domain uses CAA records, they must allow both authorities. See What DNS types can I use? for the exact records. On the Pro plan and up you can also opt in to short-lived certificates.

Security

We only support current TLS versions and keep the cipher configuration up to date. Our HTTPS redirects hold an A+ rating from Qualys SSL Labs, on every plan, including Free.

A+ rating on Qualys SSL Labs

Want to go further? Enable HSTS to make browsers always use HTTPS for your hostnames.

More articles

Setup & Configuration
What are these DNS changes?
What DNS types can I use?
How long does the DNS change take?
Troubleshooting new redirects
Redirecting non-www to www
Redirect settings
Matching
Regex matching
Wildcard subdomains
Destination variables
Dynamic destinations
Redirect flattening
SSL profiles
robots.txt
Monitoring redirect.pizza itself
Features
Automatic HTTPS
Automatic DNS
Nameservers
Analytics
Broken destination monitoring
Email forwarding
Pause and resume
Dedicated IP
API
MCP
Zapier
Terraform provider
Security & Account
Team management
Two-factor authentication
SAML SSO
SSO via Okta
Summary email
HSTS (HTTP Strict Transport Security)
Prevent foreign embedding
Web Application Firewall (WAF)
Security & compliance
Subprocessors
Service level agreement (SLA)
Walkthroughs
GoDaddy: Forwarding with HTTPS support
Namecheap: Forwarding with HTTPS support
Cloudflare: Forwarding with HTTPS support
Network Solutions: Forwarding with HTTPS support
Hover: Forwarding with HTTPS support
Amazon Route 53: Forwarding with HTTPS support
Google Cloud DNS: Forwarding with HTTPS support
Azure DNS: Forwarding with HTTPS support
DigitalOcean: Forwarding with HTTPS support
NS1: Forwarding with HTTPS support
DNS Made Easy: Forwarding with HTTPS support
TransIP: Forwarding with HTTPS support
EuroDNS: Forwarding with HTTPS support
Mijndomein: Forwarding with HTTPS support
Freenom: Forwarding with HTTPS support