SSL profiles

redirect.pizza installs and renews SSL certificates for your hostnames automatically, so your redirects work over both http:// and https:// without you managing certificates. The SSL profile determines how long those certificates are valid and how often they're renewed.

Default profile

By default we use the tlsserver profile from Let's Encrypt. Certificates issued with this profile are valid for 45 days and are renewed well before they expire.

If Let's Encrypt is unavailable, rate limited or unable to issue a certificate, we fall back to ZeroSSL automatically. Certificates from ZeroSSL are valid for 90 days.

Short-lived certificates

Available from the Pro plan and up.

You can opt in to short-lived certificates, which use the shortlived profile from Let's Encrypt. These certificates are valid for 160 hours, just over 6 days, and are renewed far more often. Choose this if your security policy asks for short certificate lifetimes and you're comfortable relying fully on automatic renewal.

Modes

  • Preferred: we try to issue a short-lived certificate first. If that fails, we fall back to a regular certificate. This is the default and recommended mode.
  • Strict: we only issue short-lived certificates. If issuance fails, we don't fall back to a regular certificate, and the hostname may temporarily be without a valid certificate.

For most teams Preferred is the right choice: you get short-lived certificates when everything works and a regular certificate as a safety net when it doesn't. Use Strict only if short lifetimes are a hard requirement.

What changes

Your redirects keep working exactly the same way. The only differences are the validity period and the renewal frequency:

  • Regular Let's Encrypt certificates (tlsserver): valid for 45 days.
  • Short-lived certificates (shortlived): valid for 160 hours.

You don't need to change DNS or renew anything by hand. redirect.pizza handles the whole process.

When a new profile takes effect

Changing the SSL profile doesn't replace the current certificate immediately. The new profile is used at the next renewal, so the active certificate stays in place until then.

Need help?

Not sure which profile fits your setup? Contact us via the chat or email support@redirect.pizza. We're happy to help.

More articles

Setup & Configuration
What are these DNS changes?
What DNS types can I use?
How long does the DNS change take?
Troubleshooting new redirects
Redirecting non-www to www
Redirect settings
Matching
Regex matching
Wildcard subdomains
Destination variables
Dynamic destinations
Redirect flattening
SSL profiles
robots.txt
Monitoring redirect.pizza itself
Features
Automatic HTTPS
Automatic DNS
Nameservers
Analytics
Broken destination monitoring
Email forwarding
Pause and resume
Dedicated IP
API
MCP
Zapier
Terraform provider
Security & Account
Team management
Two-factor authentication
SAML SSO
SSO via Okta
Summary email
HSTS (HTTP Strict Transport Security)
Prevent foreign embedding
Web Application Firewall (WAF)
Security & compliance
Subprocessors
Service level agreement (SLA)
Walkthroughs
GoDaddy: Forwarding with HTTPS support
Namecheap: Forwarding with HTTPS support
Cloudflare: Forwarding with HTTPS support
Network Solutions: Forwarding with HTTPS support
Hover: Forwarding with HTTPS support
Amazon Route 53: Forwarding with HTTPS support
Google Cloud DNS: Forwarding with HTTPS support
Azure DNS: Forwarding with HTTPS support
DigitalOcean: Forwarding with HTTPS support
NS1: Forwarding with HTTPS support
DNS Made Easy: Forwarding with HTTPS support
TransIP: Forwarding with HTTPS support
EuroDNS: Forwarding with HTTPS support
Mijndomein: Forwarding with HTTPS support
Freenom: Forwarding with HTTPS support

Can’t find the answer you’re looking for?

24 hours
E-mail us
support@redirect.pizza
Start a chat
Online 9:00 - 21:00 CEST
Phone
Available with Enterprise
Pricing Background
Domain redirects delivered hassle-free

Get started right away

  • Free plan
  • No creditcard required
Features

Everything
you need