How to change your WordPress URL without locking yourself out
Change "WordPress Address (URL)" and "Site Address (URL)" under Settings, then General, or set them in wp-config.php or with WP-CLI. Then replace the old address stored in your content, redirect the old address to the new one, and tell search engines if the domain changed.
- By
- WP Ministry
- Published
In short
- WordPress keeps its address in two settings. On most sites both hold the same value.
- Change them in the dashboard if you can. wp-config.php, WP-CLI and the database are for when you cannot.
- The new address must already reach the site, with a working certificate, before you save.
- The old address is also stored throughout your content. Replace it with a tool that understands serialized data, never with a plain find and replace.
- Redirect every old address to the same page at the new one, and keep the redirects for at least a year.
- A wrong address locks you out of the dashboard. Two lines in wp-config.php get you back in.
WordPress reads its own address from two settings and builds its links, the addresses of its stylesheets and scripts, and its login redirects from them. Changing the site's address means changing those two settings, and then dealing with the copies of the old address that are stored everywhere else.
That covers a new domain, a move from http to https, adding or dropping www, and moving a site out of a subfolder. The steps here are for a single site. A multisite network keeps its addresses in more places and is moved differently.
The two settings
Both are under Settings, then General.
- "WordPress Address (URL)" is the address of the folder that holds WordPress's own files, such as
wp-adminandwp-includes. In the database it is the option namedsiteurl. - "Site Address (URL)" is the address people type to reach the site. In the database it is
home.
WordPress's documentation says the two are identical unless WordPress has been given a folder of its own. So on most sites you change both, to the same value. Write the full address with https:// in front and no slash at the end.
| Change | Set both addresses to | Also needed |
|---|---|---|
| http to https | The same address with https:// | A working certificate first, then the stored http:// addresses replaced |
Adding or dropping www | The form you want to keep | A certificate that covers that form |
| A new domain | The new domain | The new domain pointed at the site, a certificate for it, the stored addresses replaced, redirects from the old domain |
| Out of a subfolder | The address without the subfolder | The settings changed before the files are moved |
Before you change anything
- Take a backup of the database and the files. With WP-CLI,
wp db export ~/before-address-change.sqlwrites the database to a file in your home folder. Download it, and delete it from the server when you are done. - Check that the new address already reaches the server. For a new domain, add it to your hosting account and point its DNS there first.
- Check the certificate. Open the new address with
https://in front. A certificate lists the names it is valid for, so one issued for the old name does not cover the new one. If the browser shows a warning, fix that first: see how to fix "Your connection is not private". - Try it on a staging copy of the site first, if you have one.
Four ways to change the address
Use the first one that is open to you.
In the dashboard
Step 1: Go to Settings, then General
The two fields are near the top.
Step 2: Change both addresses
Type the new address into "WordPress Address (URL)" and "Site Address (URL)". Check it letter by letter.
Step 3: Press Save Changes
WordPress now answers at the new address. Log in again there.
If the two fields are greyed out, the addresses are defined in wp-config.php and have to be changed in that file.
In wp-config.php
Two constants overrule what is in the database: WP_HOME for the Site Address and WP_SITEURL for the WordPress Address. Add them above the line that says "That's all, stop editing!".
define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );This works when you cannot reach the dashboard, which makes it the quickest way back in after a mistake. It does not change the values stored in the database, and while the lines are there the two fields under Settings cannot be edited. To make the change permanent, set the same addresses in the database with one of the other methods, then remove the two lines.
With WP-CLI
Over SSH, from the site's folder. The first two commands show what is stored now, and the last two change it.
wp option get home
wp option get siteurl
wp option update home 'https://example.com'
wp option update siteurl 'https://example.com'If wp-config.php defines WP_HOME or WP_SITEURL, those still win.
In the database, as a last resort
With no dashboard, no WP-CLI and no way to edit wp-config.php, change the two values by hand. Back up the database first. In your host's database tool, usually phpMyAdmin, open the wp_options table. The prefix may differ from wp_. Find the rows named siteurl and home, which may be on different pages of the table, and edit the option_value of each.
Change those two values and nothing else. Do not use the tool's find and replace on the whole database.
Replace the old address stored in your content
The two settings are not the only place the address lives. An image placed in a post is saved with its full address. So are links between your pages, and many theme and plugin settings. After a change of domain those still point at the old one. After a move to https they still say http://, which is what causes mixed content warnings.
A plain find and replace, in a database tool or in an exported .sql file, breaks some of them. Themes and plugins store many settings as serialized data, which records the length of each piece of text beside the text. WordPress's documentation puts it this way: values are stored "with the length of your URL marked. When this changes, things break." Swap in an address of a different length and the recorded length no longer matches, and the setting cannot be read.
WP-CLI's search-replace command handles serialized data and corrects the lengths.
Step 1: Do a dry run
Use your own old and new addresses, exactly as they appeared in the two settings.
--dry-runlists each table and column that holds the old address and how many replacements it would make, and saves nothing.bashwp search-replace 'https://old-example.com' 'https://new-example.com' --skip-columns=guid --report-changed-only --dry-runStep 2: Run it for real
The same command without
--dry-run. It cannot be undone except by restoring the backup.Step 3: Repeat for the other forms of the old address
Run it again for the old address with
http://, and with or withoutwww, if the site was ever reached that way.Step 4: Empty every cache
Clear your caching plugin, your host's cache and any CDN, then look at the site.
--skip-columns=guid leaves alone the permanent identifier WordPress gives each post. Feed readers use it to tell which posts they have already shown, and WordPress's instructions are never to change it, even when the domain changes.
The command searches the tables WordPress itself registers. Add --all-tables-with-prefix to include tables that plugins have added.
Without WP-CLI, use a search and replace plugin that says it handles serialized data and offers a dry run. WordPress's documentation names Better Search Replace for this.
Moving out of a subfolder
To move a site from example.com/blog to example.com, the order matters. WordPress's instructions are to change the two addresses under Settings, then General first, save, and only then move the files, without opening the site in between. Then log in at the new address, go to Settings, then Permalinks and press Save Changes so that the rewrite rules are written for the new location, and run the search and replace above for the old folder's address.
If you move the files first, the settings still name the old folder and the dashboard will not load. Set the two addresses in wp-config.php to get back in.
Redirect the old address
Anyone who follows an old link, and every search engine that knows the old address, should land on the same page at the new one.
For www this takes care of itself when both forms reach the same WordPress: it sends visitors to the host name in the Site Address. For http to https, many hosting control panels have a switch that forces HTTPS. If yours does not, ask the host to add the redirect. For a new domain, add a redirect on the old domain that keeps the rest of the address. Your hosting control panel may have a tool for this. By hand, it looks like this:
.htaccess
RewriteEngine On
RewriteCond %{HTTP_HOST} ^(www\.)?old-example\.com$ [NC]
RewriteRule ^(.*)$ https://new-example.com/$1 [R=301,L]On Apache the rules go in the .htaccess file of the folder the old domain is served from. If that file also holds WordPress's rules, put these above the line # BEGIN WordPress. On nginx, the old domain's server block for port 443 needs the same return line beside its certificate settings.
Keep the old domain registered and its certificate current while the redirect runs. A browser checks the certificate before it follows the redirect, so an expired one stops visitors at a warning.
Do not send every old address to the new home page. Google's guidance is to redirect each old address to its own new one, in one step.
Tell search engines
Redirects do most of this. Google treats a new domain and a move to https alike as a site move, follows permanent redirects and passes what it knows about the old addresses to the new ones.
- Verify the new address in Google Search Console, and keep the old one verified.
- For a new domain or subdomain, use the Change of Address tool there. Google says it is not needed for a move to https or between
wwwand nowww. - Submit the sitemap at the new address. WordPress's own is at
/wp-sitemap.xml, unless an SEO plugin provides a different one.
Google says to expect rankings to move about while it reads the site again, and that for a medium-sized site it can take a few weeks or more for the new addresses to show.
If the new address locks you out
A mistyped address, or one that does not reach the site yet, leaves the dashboard unreachable or the login page reloading. Nothing is lost. Add the two lines from "In wp-config.php" above with the address that does work, using your host's file manager or SFTP. The site answers at once and you can log in.
Then put the right values in the database, under Settings or with WP-CLI, and remove the two lines. If the login page still keeps coming back, work through the login page that keeps refreshing.
Common questions
Do I need to change the address when I move to a new host?
No, not if the domain stays the same. The two settings stay as they are and only the DNS changes. That is a different job from this one. Our WordPress migration service moves one site from one host to another and tests the copy on the new host before the DNS is changed.
How long should I keep the old domain?
Google's guidance is to keep the redirects for as long as possible, and generally for at least a year. Keep the old domain registered, and its certificate current, for all of that time.
Images still load from the old address. Why?
Their addresses are stored in the content, not built from the two settings. Run the search and replace again with --dry-run for each form of the old address, add --all-tables-with-prefix in case a plugin keeps them in a table of its own, and empty every cache.
- ResourceWebsite migration checklist: before, during and after the move
- ResourceWebsite redesign SEO checklist: what to record, map and check on a rebuilt site
- Cost guideWordPress migration cost: which job you are being quoted for, and what moves the price
- GuideHow to move WordPress to a new domain and keep your links and search traffic
- GuideHow to switch from Elementor to the WordPress block editor (Gutenberg)
- GuideTraffic dropped after a website redesign: what to check on a WordPress site, in order

