www vs non-www for a WordPress site: which to choose, and how to make every other form redirect to it
Google's documentation prefers https over http and states no preference between www and the bare domain. It says to pick one address and redirect the others. WordPress redirects www against non-www for its own pages and nothing more. The rest is a rule on the server.
- By
- WP Ministry
- Published
- Tested on
- WordPress 7.1.3, PHP 8.3.35
In short
- A site can answer at four forms of its address, http or https, with www or without. To a search engine each is a different address for the same pages.
- Google's documentation prefers https to http. Between www and the bare domain it states no preference and says to pick one.
- WordPress keeps the choice in two settings and sends the other of the two host names to it with a 301.
- That redirect covers the pages WordPress builds. It does not cover files, the login page, http against https, or any third name that reaches the site.
- A rule in .htaccess above WordPress's block closes those gaps. It has to name the same host as the settings, or the site loops.
- Check with four requests. One form answers 200 and the other three answer 301 straight to it.
A site can usually be reached at four forms of its address: http://example.com, http://www.example.com, https://example.com and https://www.example.com. To a search engine each is a different address for the same pages. Google's documentation prefers https over http. Between www and the bare domain it states no preference: it says to pick one address and redirect the others to it.
So nothing in that documentation makes one of the two the better choice. What matters is that the other three forms each answer with a 301 that leads straight to the one you chose. WordPress does part of that by itself. For the pages it builds, it sends the www form to the bare one, or the reverse. It does not send http to https, it does not cover files or the login page, and it leaves any other name alone.
Four addresses, one site
Google's documentation calls the same page at several addresses duplicate content, and names the http and https versions of a site among its ordinary causes. It groups the copies and chooses one, the canonical, to show in results. Three things it says decide the rest of this page.
- A redirect counts for a lot. Its page on canonical addresses lists a redirect first and calls it "a strong signal that the target of the redirect should become canonical". A
rel="canonical"link is also rated strong, a sitemap entry weak, and the methods add up when used together. - It prefers https. An https page is chosen over the same page on http, unless something speaks against it: a certificate that is not valid, or an https page that redirects to http.
- It has no stated preference for or against
www. Its own example gives one home page reachable at three addresses, one of them withwww, and says to pick one and redirect the others to it.
The same documentation says duplicate content of this kind is normal and is not a breach of its spam policies, and that a site which states no preference will mostly be fine, because Google then picks an address itself. WordPress's reference for its own redirect still speaks of preventing a penalty for duplicate content. Google's pages describe no such penalty. The reasons they give for settling on one address are practical: you choose which address people see, links to the other forms are counted toward it, your reports are in one place, and crawling time is not spent on copies.
Where WordPress keeps your choice
WordPress stores its address in two settings under Settings, then General: "WordPress Address (URL)" and "Site Address (URL)". Whatever host name and scheme they hold is the form WordPress treats as its own. How to change your WordPress URL covers what each is for and every way to change them. To read them with WP-CLI:
wp option get home
wp option get siteurlhttps://example.com
https://example.comThe first line is the Site Address and the second the WordPress Address. If wp-config.php defines WP_HOME or WP_SITEURL, those overrule the database, and the commands print the values in use.
What WordPress redirects by itself
This asks for a page under the www name, without its final slash, on a site whose settings hold https://example.com. It prints the status and where the answer leads.
curl -sI https://www.example.com/sample-page | grep -i -E "^(HTTP|location|x-redirect-by)"HTTP/1.1 301 Moved Permanently
X-Redirect-By: WordPress
Location: https://example.com/sample-page/One answer corrected the host and the slash together, and the X-Redirect-By line says WordPress sent it. The function behind it is redirect_canonical(). This is what it did with each request under the www name:
Asked for at www.example.com | Answer |
|---|---|
| The home page | 301 to example.com/ |
| A page, or a post | 301 to the same page at example.com |
| A page without its final slash | 301 to the page with its slash at example.com, in one hop |
A page with ?utm_source=newsletter added | 301 to the same address at example.com, with the addition kept |
/robots.txt, /wp-sitemap.xml | 301 to the same address at example.com |
A search results page, /wp-json/ | 200 |
/wp-login.php | 200. The login page loads under www |
| An image file | 200. The server sends it without asking WordPress |
With www in the settings it runs the other way: the bare name is sent to www.
Where it stops
- Files and the login page. The redirect runs when WordPress builds a page. A file is sent by the web server, and the login page does not run it, so both answer under either name.
- Any other name. WordPress's source compares the two host names and redirects only when they differ by
www.at the front. A request under a third name that reaches the same site, such as a second domain on the hosting account, a host's temporary address or another subdomain, got a 200 and the page. - http against https. The comparison is of host and path, not scheme. With
https://example.comin the settings, a page asked for over http answered 200 over http. Asked for over http underwww, it answered 301 tohttp://example.com/sample-page/: the right name, still on http. Only the login page and the dashboard moved. Each answered 302 to its https address, which WordPress does whenever the WordPress Address begins with https. - Capital letters.
/Sample-Page/answered 200 and was not sent to/sample-page/. - A request that never arrives. WordPress cannot redirect what it never receives. If DNS has no record for the other name, nothing answers. If the certificate does not cover it, a browser stops at a certificate warning before it reads any redirect. If the server shows a different site under that name, that site answers.
- A wp-config.php that builds the address from the request. WordPress's documentation shows
WP_HOMEandWP_SITEURLset from the Host header of each request. A site set up that way has no address of its own. It answered 200 under every name tried and redirected none of them.
The canonical link
On posts and pages WordPress also prints a rel="canonical" link, the second strong signal on Google's list. This reads it from a page:
curl -s https://example.com/sample-page/ | grep -o '<link rel="canonical"[^>]*>'<link rel="canonical" href="https://example.com/sample-page/" />It is built from the settings, not from the request. The same page asked for under a third name, in capital letters, and over http when the settings said https, printed the same link each time. So a copy that WordPress does not redirect still names the real address. The one exception is the last item in the list above, where the link follows whatever name was asked for.
The sitemap goes further. /wp-sitemap.xml was the one address WordPress sent to the settings' form whatever was asked: under a third name, and over http when the settings said https, it answered 301.
The link is printed on a single post or page. The home page here, a list of the latest posts, had none. WordPress SEO without a plugin lists which pages have one.
Redirect at the server
A rule in the web server answers before WordPress is asked, so it covers files and the login page as well, and it can send a request to the right name and to https in one hop. On Apache it goes in the .htaccess file in the site's folder, above the line # BEGIN WordPress, so that it is read before WordPress's own rules.
.htaccess
RewriteEngine On
RewriteCond %{HTTP_HOST} ^www\.example\.com$ [NC]
RewriteRule ^ https://example.com%{REQUEST_URI} [R=301,L]The condition names the host to send away, with a backslash before each dot. The rule gives the address to send it to, and %{REQUEST_URI} keeps the rest of the address, so a deep page goes to the same page and not to the home page. With the first rule in place, a page, an image and /wp-login.php asked for under www each answered 301 to the same path at the bare name. The answer came from the server, with no X-Redirect-By line, and following it reached the page in one hop. An address under www that also lacked its final slash took two: the server corrected the name, and WordPress then added the slash.
These rules act on the host name only. http://example.com, the right name on the wrong scheme, still needs its own redirect to https. Your hosting panel may have a switch for that, and moving a site to HTTPS has the rule and the cases where it loops. A third name needs a condition of its own, or its own redirect in the hosting panel.
The rules are for Apache. On another web server the redirect is written in that server's configuration, which on managed hosting is the host's to add. How to set up redirects covers the places a redirect can live.
Check all four forms
This asks for the home page at each form, follows nothing, and prints the status and where each answer points.
for address in http://example.com/ http://www.example.com/ https://example.com/ https://www.example.com/; do
curl -s -o /dev/null -w "$address: %{http_code} %{redirect_url}\n" "$address"
doneOn a site that is set up to answer at https://example.com, it reads:
http://example.com/: 301 https://example.com/
http://www.example.com/: 301 https://example.com/
https://example.com/: 200
https://www.example.com/: 301 https://example.com/One line says 200, and the other three say 301 and name that one address. Anything else is worth a look:
- Two lines say 200. Two forms serve the site and nothing joins them.
- A 301 points at a form that itself answers 301. That is a chain.
http://www.example.com/leading tohttp://example.com/and then to https is the one shown above: WordPress corrects the host and keeps http, and the server then moves it to https. Google's guidance on moves is to redirect to the final address directly. - 302 in place of 301. Google's page on redirects says it uses a permanent redirect as a signal that the target should be the canonical address, and does not use a temporary one that way.
- 000. curl got no answer at that address. Look at the DNS record and the certificate for that name.
Run it again with a deep page in place of each /, because a redirect that sends every address to the home page passes the first test and fails this one. Without a terminal, the redirect checker follows one address at a time and shows every hop.
Which one to choose
For a site that is already live, keep the form it has. Changing it is a move, covered below.
For a new site, Google's documentation gives no reason to prefer either. The differences are practical.
- DNS. The DNS rules do not let an alias record (a CNAME) share a name with other records, and the bare domain always has others. A CDN or a host that asks you to point your name at theirs with a CNAME can be given
www, which needs no other records. At the bare domain it depends on what your DNS provider offers, so ask before you choose. - Cookies. Under the cookie standard, a cookie set without a
Domainattribute goes back only to the host that set it, whichever form that is. One set forexample.comby name goes to every subdomain as well. If other things run on subdomains of the same domain and should not receive the site's cookies,wwwgives the site a name of its own. - The certificate. Whichever you choose, the certificate has to cover both names, or the redirect from the other one is never reached.
In Search Console
Search Console has two kinds of property, and they count these forms differently.
- A Domain property, added as
example.com, includes every subdomain,wwwamong them, on http and https. It is verified with a DNS record. - A URL-prefix property covers only addresses that begin exactly as typed, scheme and host included.
https://example.com/leaves out everything athttps://www.example.com/and everything on http.
A Domain property shows all four forms in one place. With URL-prefix properties, Google's help says to add one for each form.
Changing from one to the other later
Changing a live site from one form to the other changes the address of every page, so it is a small site move. Google's page on moves lists a change from http to https, and a merging of host names, among its examples. It says the Change of Address tool is not needed for a switch between www and non-www on the same domain, and that redirects should stay for as long as possible, generally at least a year.
In WordPress the work is the two settings, the old form stored in content, and the redirect. How to change your WordPress URL has each step and the way back if the new address locks you out. After a move to https, addresses stored with http cause mixed content warnings.
When to get help
- Ask the host if one of the four forms answers nothing or shows a certificate warning. Both come down to DNS or the certificate, which are set outside WordPress.
- Hand it over if the four requests show a chain, or two forms answering 200, and you cannot find where each redirect is set. SEO for a new website from WP Ministry is a one-time setup for a new or rebuilt WordPress site, and this is one of its parts: http, https, www and the bare name all end at the same place, in one hop.
Common questions
Is www or non-www better for SEO?
Google's documentation states no preference between them. It says to pick one address and redirect the others to it. It does state a preference between http and https, for https.
Google shows both forms of my site. Is that a penalty?
No. Google's documentation says duplicate addresses of this kind are normal and not a breach of its spam policies, and that it chooses one to show. To settle which one, run the four requests above, fix whatever does not answer 301 to your chosen form, and leave the redirects in place.
Does WordPress redirect http to https by itself?
Not for the pages of the site. It compares the host name and the path of a request with its settings, not the scheme. It does redirect the login page and the dashboard to https when the WordPress Address begins with https. The rest is a rule on the server or a switch in the hosting panel.
I added the rule and now the site says too many redirects. Why?
The rule and WordPress's settings name different hosts, so each sends the request back to the other. Take the rule out, read the two settings, and add the rule that matches them. ERR_TOO_MANY_REDIRECTS covers the other causes.
- Error fix"Not found (404)" in Search Console: which addresses to fix on a WordPress site, and which to leave
- Error fix"Page with redirect" in Search Console: what it means on a WordPress site, and which ones to fix
- ResourceWebsite redesign SEO checklist: what to record, map and check on a rebuilt site
- ResourceWordPress SEO audit checklist: what to check, in order, and how to check each item
- Error fix"Alternate page with proper canonical tag" in Search Console: what it means on a WordPress site
- Error fix"Blocked by robots.txt" in Search Console: when it is fine, and how to find the rule on WordPress

