Websites and Tech

.htaccess File

Also called .htaccess, htaccess

A configuration file on Apache and LiteSpeed servers that controls redirects, HTTPS, caching and access rules for a folder and everything in it.

Quick facts: .htaccess File

Category
Websites and Tech
Also called
.htaccess, htaccess
Level
Intermediate
Affects
Redirects, HTTPS, site speed through caching, security, server errors
Where to see it
Hosting file manager or cPanel, an SFTP client, Screaming Frog or another crawler, browser developer tools, curl
In this article4
  1. How an .htaccess file works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

An .htaccess file is a small configuration file that sits in a folder on an Apache web server, and on LiteSpeed servers that read the same format, and changes how the server handles requests for that folder and everything beneath it. On a typical WordPress site it powers readable permalinks, and it is where many redirects, HTTPS rules and access restrictions are written.

How an .htaccess file works

The name starts with a dot, which makes it a hidden file on most systems, so you may need to switch on “show hidden files” in your file manager or SFTP client to see it. Each time someone requests a page, the server reads the .htaccess files in the folders along the way and applies their instructions before sending a response.

Those instructions are called directives. The common ones in marketing and SEO work:

  • Redirects. A line such as Redirect 301 /old-page/ https://www.example.co.uk/new-page/ sends one URL to another. RewriteRule, from the mod_rewrite module, handles patterns, such as sending every http:// request to https:// or every non-www address to www.
  • Caching headers that tell browsers how long to keep images, CSS and scripts.
  • Access rules that block certain files, folders or IP addresses, or password-protect a staging area.
  • Custom error pages for 404 and other errors.

Order matters, because rules are processed from the top down. WordPress writes its own block between the lines “# BEGIN WordPress” and “# END WordPress” and rewrites that block when permalinks are saved, so custom rules belong above it. Nginx servers, common on managed and cloud hosting, ignore .htaccess entirely: the same rules go in the server configuration instead.

Why it matters

Many of the technical signals Google reads are decided here. Whether the site answers on one version only (https, with or without www), whether old URLs pass their value to new ones through a 301 redirect, and whether trailing slashes are handled consistently can all come down to a few lines in this file.

It is also fragile. A single typo produces a 500 Internal Server Error on every page of the site, and a badly ordered set of rules can send visitors through a redirect chain of three or four hops before they reach a page. Because many UK shared hosting plans run Apache or LiteSpeed, most small business sites on cPanel hosting have an .htaccess file doing more than the owner realises.

Common mistakes

  • Editing the live file with no copy. When the site breaks, nobody knows what it said before.
  • Rules placed inside the WordPress block Which disappear the next time permalinks are saved.
  • HTTPS and www handled in separate rules Creating two hops instead of one.
  • Plugins fighting. Security, caching and redirect plugins all write to the same file and can override one another.
  • Thousands of one-off redirects after several redesigns, read on every single request.

How to act on it

Download a copy of the current file before you change anything, and test changes on a staging site first where you can. After any edit, check a handful of URLs in a browser and with a crawler: the old addresses should return a single 301 to a page that returns 200, and the site should load normally.

Once a year, read the file from top to bottom. Remove rules for things that no longer exist, combine HTTPS and www handling into one step, and replace long lists of individual redirects with pattern rules where the URLs follow a pattern. If you would rather someone else untangled it, redirect and server configuration clean-up is part of my technical SEO work.

Do and do not

Do

  • Keep a copy of the file before every edit
  • Place custom rules above the WordPress block
  • Test redirects for single hops after each change

Do not

  • Edit the live file with no backup
  • Handle HTTPS and www in separate rules
  • Let several plugins write conflicting rules

Questions people ask about this

Where is the .htaccess file on a WordPress site?

It sits in the root folder of the WordPress install, the same folder that holds wp-config.php. It is hidden by default, so turn on hidden files in your hosting file manager or SFTP client. If there is none, saving the permalink settings in WordPress usually creates it, provided the server allows it.

Does my site use .htaccess?

Only if it runs on Apache or LiteSpeed. Many shared hosting plans with cPanel do; many managed WordPress and cloud hosts use nginx, which ignores the file. Your host's documentation or support team can tell you which server you are on and where redirects should go.

Is it safe to add redirects to .htaccess myself?

It is safe if you keep a copy of the original, add one rule at a time and test straight away. A mistake usually shows up immediately as a server error, and restoring the copy fixes it. For a large number of redirects, a redirect plugin or a pattern rule written by someone experienced is often the better route.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.