Your website can be reached in at least four ways: http://example.co.za, http://www.example.co.za, https://example.co.za and https://www.example.co.za. Pick one of them as the canonical address, make sure the SSL certificate covers both the bare domain and www, and send the other three to it with a permanent 301 redirect. Whether you choose www or not matters far less than choosing one and being consistent everywhere.
This guide explains the choice, the redirect types and how to set it up on the platforms our customers use most.
Why one address matters
If all four versions load the same page without redirecting, you have four copies of your site as far as a search engine is concerned. Google usually works out which one to show, but it splits signals such as links between the versions while it does, and it might pick a version you didn't intend. Visitors also get a different padlock experience depending on how they arrived, and analytics, cookies and sign-in sessions can behave differently on each host.
One canonical URL fixes all of that.
www or non-www?
Both work. Some practical differences:
www.example.co.za |
example.co.za |
|
|---|---|---|
| Looks | Traditional, clearly a website | Shorter, modern |
| DNS flexibility | www can be a CNAME, handy for some platforms and CDNs |
The bare domain can't be a CNAME, only A/AAAA (or a provider-specific alias record) |
| Cookies | Cookies set on www don't leak to other subdomains |
Cookies set for the bare domain may be sent to subdomains if you scope them to the domain |
If you are starting fresh and plan to use a CDN or a hosted platform that prefers CNAMEs, www is slightly more flexible. If your brand and printed material already use the bare domain, keep it. Never switch back and forth.
Redirect types in one minute
- 301 Moved Permanently: "this address has moved for good". Search engines transfer the old URL's signals to the new one. Use this for canonical host and HTTPS redirects.
- 308 Permanent Redirect: the same as 301 for search purposes, but it guarantees the browser keeps the request method. Next.js uses 308 for permanent redirects.
- 302 Found / 307 Temporary Redirect: "use this other address for now". Search engines keep the original URL indexed. Don't use these for a permanent move.
Keep it to one hop. http://example.co.za should go straight to https://www.example.co.za, not to https://example.co.za first and then to www. Each extra hop slows the first visit down.
Step 1 - DNS and SSL for both names
Both the bare domain and www need DNS records pointing at your hosting, and your certificate must cover both, otherwise visitors on the non-canonical name see a certificate warning before the redirect even runs. With NewHost, the free Let's Encrypt certificate covers your domain and www. If you're unsure about records, see how to point your domain to your hosting and SSL certificates explained.
Step 2 - Set up the redirects
Plesk (classic websites and WordPress on NewHost web hosting)
Open the control panel from your hosting account, then the domain's Hosting settings:
- set Preferred domain to the
wwwor non-wwwversion. Plesk then redirects the other one with an SEO-safe 301; - tick the option for a permanent SEO-safe 301 redirect from HTTP to HTTPS.
That handles all four versions without touching any files. Our Plesk hosting guide shows where the other settings live.
Apache .htaccess
If you prefer to manage it in the site's files, this redirects everything to https://www.example.co.za in one hop:
RewriteEngine On
RewriteCond %{HTTPS} off [OR]
RewriteCond %{HTTP_HOST} !^www\.example\.co\.za$ [NC]
RewriteRule ^ https://www.example.co.za%{REQUEST_URI} [L,R=301]
Use one method, not both, so redirects don't fight each other.
WordPress
Set Settings, General, WordPress Address and Site Address to your canonical https:// URL. WordPress then generates links with that host. Do this together with the server redirect above, and update any hard-coded http:// links in content. See WordPress hosting in South Africa for more on running WordPress well.
Next.js
Add a host-based redirect in next.config.ts:
import type { NextConfig } from "next";
const nextConfig: NextConfig = {
async redirects() {
return [
{
source: "/:path*",
has: [{ type: "host", value: "example.co.za" }],
destination: "https://www.example.co.za/:path*",
permanent: true,
},
];
},
};
export default nextConfig;
HTTP to HTTPS is normally handled in front of the app by the web server, so the app only needs to fix the host.
Express
Behind a reverse proxy, tell Express to trust the forwarded protocol, then redirect anything that isn't the canonical origin:
const CANONICAL = "www.example.co.za";
app.set("trust proxy", 1);
app.use((req, res, next) => {
if (process.env.NODE_ENV !== "production") return next();
if (req.secure && req.hostname === CANONICAL) return next();
res.redirect(301, `https://${CANONICAL}${req.originalUrl}`);
});
Step 3 - Make everything else agree
Redirects are the safety net. Everything you control should point at the canonical URL directly:
- Canonical tags on every page (
<link rel="canonical" href="https://www.example.co.za/...">). - Internal links, menus and images.
- Your sitemap must list only canonical URLs. See Next.js sitemap and robots.txt.
- Google Business Profile, social profiles and email signatures.
- Google Search Console: a Domain property covers every version at once. See verifying your domain in Search Console.
Trailing slashes
/about and /about/ are also two different URLs. Most frameworks pick one style and redirect the other. Check that yours does, and that your canonical tags and sitemap use the same style.
Step 4 - Test it
curl -sI http://example.co.za/about | grep -iE "^(HTTP|location)"
curl -sI http://www.example.co.za/about | grep -iE "^(HTTP|location)"
curl -sI https://example.co.za/about | grep -iE "^(HTTP|location)"
Each should return a 301 (or 308) with a location of https://www.example.co.za/about, and the canonical URL itself should return 200. If you see two redirects in a row, or a 302, fix the rule.
Frequently asked questions
Will switching from non-www to www hurt my rankings?
A clean, permanent, one-hop redirect from every old URL to its new equivalent keeps the disruption small. Expect search results to update over the following weeks. Avoid switching more than once.
Do I still need the redirect if I have canonical tags?
Yes. Canonical tags are a hint for search engines; redirects make sure people and links always land on the right address. Use both.
Why does the non-www address show a certificate warning?
The certificate doesn't cover that name, so the browser warns before it ever sees your redirect. Issue a certificate that includes both names.
Is HTTPS required for a site without forms or payments?
Browsers mark plain HTTP pages as "Not secure", and HTTPS is a search ranking signal. With free certificates there is no reason to skip it.
Running a website in South Africa? NewHost web hosting includes free Let's Encrypt SSL for your domain and www, with Plesk's redirect settings ready to use.