SSL profiles

redirect.pizza installs and renews SSL certificates for your hostnames automatically, so your redirects work over both http:// and https:// without you managing certificates. The SSL profile determines how long those certificates are valid and how often they're renewed.

Default profile

By default we use the tlsserver profile from Let's Encrypt. Certificates issued with this profile are valid for 45 days and are renewed well before they expire.

If Let's Encrypt is unavailable, rate limited or unable to issue a certificate, we fall back to ZeroSSL automatically. Certificates from ZeroSSL are valid for 90 days.

Short-lived certificates

Available from the Pro plan and up.

You can opt in to short-lived certificates, which use the shortlived profile from Let's Encrypt. These certificates are valid for 160 hours, just over 6 days, and are renewed far more often. Choose this if your security policy asks for short certificate lifetimes and you're comfortable relying fully on automatic renewal.

Modes

  • Preferred: we try to issue a short-lived certificate first. If that fails, we fall back to a regular certificate. This is the default and recommended mode.
  • Strict: we only issue short-lived certificates. If issuance fails, we don't fall back to a regular certificate, and the hostname may temporarily be without a valid certificate.

For most teams Preferred is the right choice: you get short-lived certificates when everything works and a regular certificate as a safety net when it doesn't. Use Strict only if short lifetimes are a hard requirement.

What changes

Your redirects keep working exactly the same way. The only differences are the validity period and the renewal frequency:

  • Regular Let's Encrypt certificates (tlsserver): valid for 45 days.
  • Short-lived certificates (shortlived): valid for 160 hours.

You don't need to change DNS or renew anything by hand. redirect.pizza handles the whole process.

When a new profile takes effect

Changing the SSL profile doesn't replace the current certificate immediately. The new profile is used at the next renewal, so the active certificate stays in place until then.

Need help?

Not sure which profile fits your setup? Contact us via the chat or email support@redirect.pizza. We're happy to help.

More articles

Setup & Configuration
What are these DNS changes?
What DNS types can I use?
How long does the DNS change take?
Troubleshooting new redirects
Redirecting non-www to www
Redirect settings
Matching
Regex matching
Wildcard subdomains
Destination variables
Dynamic destinations
Redirect flattening
SSL profiles
robots.txt
Monitoring redirect.pizza itself
Features
Automatic HTTPS
Automatic DNS
Nameservers
Analytics
Broken destination monitoring
Email forwarding
Pause and resume
Dedicated IP
API
MCP
Zapier
Terraform provider
Security & Account
Team management
Two-factor authentication
SAML SSO
SSO via Okta
Summary email
HSTS (HTTP Strict Transport Security)
Prevent foreign embedding
Web Application Firewall (WAF)
Security & compliance
Subprocessors
Service level agreement (SLA)
Walkthroughs
GoDaddy: Forwarding with HTTPS support
Namecheap: Forwarding with HTTPS support
Cloudflare: Forwarding with HTTPS support
Network Solutions: Forwarding with HTTPS support
Hover: Forwarding with HTTPS support
Amazon Route 53: Forwarding with HTTPS support
Google Cloud DNS: Forwarding with HTTPS support
Azure DNS: Forwarding with HTTPS support
DigitalOcean: Forwarding with HTTPS support
NS1: Forwarding with HTTPS support
DNS Made Easy: Forwarding with HTTPS support
TransIP: Forwarding with HTTPS support
EuroDNS: Forwarding with HTTPS support
Mijndomein: Forwarding with HTTPS support
Freenom: Forwarding with HTTPS support

Domain redirects delivered hassle-free

Get started right away

  • Free plan
  • No creditcard required

redirect.pizza has all your favorite ingredients

Analytics

Who is still visiting those old domains? Gain valuable insight with detailed statistics and find out where the hits are coming from.

Learn more

API/MCP

Connect your software or AI clients to create redirects via our API and MCP. Automation makes your life easier.

Learn more

Destination Variables

You control how we handle your destination URL. Want to include your domain extension as a query string parameter? No problem.

Learn more

Dynamic destinations

Steer your traffic to different destinations, based on rules you define.

Learn more

Path forwarding

Keep the original path and keep it in the destination for a smooth domain migration and keeping your SEO game intact.

Learn more

Query Parameter Forwarding

Forward query parameters found on the source URL to the destination.

Learn more

Multiple Redirect Types

Choose the status code that works for you. Choose 301/307 (permanent), 302/308 (temporary) or frame your destination.

Learn more

Team management

Doing things all by yourself isn't much fun. Invite your co-workers to manage the redirects and work as a team.

Learn more

Automatic DNS

Integrate directly with your DNS provider, and apply the DNS changes from one platform.

Learn more

QR code generator

Create a QR code that you can use for marketing purposes. You can change the destination anytime after printing.

Learn more

Import & Export

Manage your redirects without losing precious time. Import and export redirects in our UX-friendly interface.

Global edge network

Redirecting in a blink of an eye; processing millions of request per hour in milliseconds.

Learn more

Broken destination monitor

Automatically checking your destinations to ensure it's reachable for everyone.

Learn more

Privacy First

We're based in Europe and are fully compliant with GDPR. Privacy-first!

Learn more

Wildcard subdomains

For when your domain utilizes a lot of different subdomains. Cover all subdomains with a single redirect.

Learn more

Tags

Group your redirects by adding tags. Keep everything organized and easy to find.

Bulk actions

Want to apply the same action for multiple redirects in one go? Do yourself a favor and start using bulk actions.

Dark mode

Give your eyes some well deserved rest by using the dark mode. Sync with your system or choose manually.

HSTS

Enable HSTS (HTTP Strict Transport Security) on team or domain level for an extra layer of protection.

Learn more

Change Destination Anytime

Once you're set up, you can change the destination URL anytime you want, and see the change in real-time.

Two-Factor Authentication

Secure your account with TOTP two-factor authentication. Scan the QR code, setup your app of choice, and you're safe(er).

Learn more

IDN Support

Add international hostnames with non-Latin characters. We ❤ that.

Support

Chat away! We're happy to help set up your account and answer your questions.