dotvitals

A permanent redirect is marked temporary

LowConfirmedQuick winhttp.redirects.temporary-for-canonical

What this check looks for

The redirect between your www and non-www addresses says 'this is temporary'. Browsers and search engines therefore keep asking for the old address every time.

Why it matters

A temporary redirect is never cached, so every visit pays the extra round trip, and search engines keep both addresses in the index instead of consolidating them onto one.

When the check passes, your report says: “The canonical redirect is marked permanent, as it should be”.

What it costs your score

When this check fails it removes 5 points from your HTTP score, before the status, confidence and repeat multipliers are applied. HTTP carries a weight of 7 in the overall score.

It shares the http.redirects family ceiling of 45 points: however many findings that family produces, together they cannot remove more than that from HTTP. One underlying problem showing up in several places is still one problem.

Severity
low
Default confidence
confirmed
Status when triggered
warn
Deduction
5 points
Family cap
http.redirects · 45
Category
HTTP
Module
Http redirects
Fix owned by
user
In the ruleset since
2026.09

How the whole score is calculated

How to fix it

Change the canonicalisation redirect to 301, or 308 where the method matters.

A temporary status is not cached, so every visitor pays for the hop every time.

  1. Change the status code on the www/non-www redirect.

  2. Roll it out at a short cache lifetime first: a 301 is cached aggressively and is awkward to take back.

How to confirm it worked

  • curl -sSI http://‹host›/ | head -1 — expect 301 or 308

A named slot like ‹domain› — and the braces left in the configuration below — is filled in with your own values when this rule appears on a report.

Remediation by platform

nginx
# One hop, straight to the canonical origin. Not http -> https -> www -> path.
server {
	listen 80;
	listen 443 ssl;
	server_name ‹host›;
	return 301 https://www.‹host›$request_uri;
}
Apache
<VirtualHost *:80 *:443>
	ServerName ‹host›
	RedirectMatch 301 ^/(.*)$ https://www.‹host›/$1
</VirtualHost>
Caddy
‹host› {
	redir https://www.‹host›{uri} permanent
}
Cloudflare
Rules → Overview → Create rule → Redirect Rule (path as at 2026-09) → single rule: When hostname equals ‹host›, Static/Dynamic redirect to https://www.‹host›/${http.request.uri.path}, status 301, preserve query string.
  • Collapse the chain into a single redirect per source host rather than chaining them.

  • Shown because the response identified Apache. Prefer the virtual host over .htaccess: .htaccess is re-read on every request and its rules run after the virtual host's, which is how these chains get long in the first place.

  • Cloudflare Redirect Rules run at the edge and apply only to requests that arrive through it. An origin reachable directly — by IP, or through a DNS record that is not proxied — still produces the chain measured here. Fix the origin's own configuration as well.

Technical detail

‹detail›

A 302 or 303 tells clients the move is temporary and the original URL should keep being requested. Choosing between the canonical and non-canonical form of your own hostname is not temporary. Use 301, or 308 if the request method must be preserved — 301 permits a client to rewrite POST to GET and 308 does not.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the http redirects checkerBuild the fix

Other http redirects checks