To redirect an obsolete URL with PHP, send a Location header with the destination and an intentional HTTP status, then stop execution with exit. For a fixed old-to-new URL mapping, a web-server rule is usually simpler; use PHP when application logic must choose the destination.
Choose PHP or a server-level redirect
Both approaches can send a visitor from an old URL to a new one, but they run at different layers. A server-level rule handles a predictable mapping before the request reaches application code. A PHP redirect runs as part of the application, which is useful when the destination depends on application logic.
| Approach | Best fit | What the visitor sees | Configuration considerations |
|---|---|---|---|
Apache Redirect or RedirectMatch |
Simple, fixed mappings or straightforward patterns | The browser navigates to the destination URL. | Requires configuration access in the relevant server context; availability and behavior differ between server configuration and .htaccess. |
Apache mod_rewrite |
Redirects that need conditions or more complex patterns | A redirect changes the browser URL; an internal rewrite does not. | Use only when its pattern and condition features are needed. Apache notes that powerful URL manipulation can create security mistakes. Apache mod_rewrite introduction; When not to use mod_rewrite. |
PHP header('Location: ...') |
The application must select the destination | The browser navigates to the destination URL. | PHP must run for the old URL, and the header must be sent before any output. |
| Internal rewrite | Serve a different resource while retaining the requested URL | The browser keeps the requested URL visible; this is not an HTTP redirect. | Use when URL visibility should not change. Apache redirecting and remapping documentation. |
For a fixed Apache mapping, the documented simple form is Redirect "/old-path" "/new-path". If you can configure the server and the destination is known in advance, this is generally more direct than routing the request through PHP. Consult the Apache documentation for the relevant configuration context and query-string behavior.
Redirect an old URL with PHP
For a fixed mapping handled by PHP, use a destination on the same site and send the response before rendering a page:
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
<?php
// redirect.php — fixed legacy URL mapping
$destination = '/new-page/';
header('Location: ' . $destination, true, 301);
exit;
The leading slash makes this example a path on the current origin rather than an arbitrary external URL. Change the destination and status to match the actual move. The example is a pattern, not a tested deployment: confirm that PHP handles requests for the old URL.
- Map the obsolete path to its intended destination. Prefer a fixed mapping or a strict allowlist over a destination taken directly from a request parameter.
- Call
header()before HTML, whitespace, or any other output. Even a byte-order mark or whitespace before<?phpcan cause output to precede the header. - Set the status deliberately; PHP’s
Location:header normally results in a 302 unless a 201 or 3xx status has already been set. The third argument toheader()supplies the status code. PHP manual:header(). - Call
exitimmediately afterward so the rest of the application does not continue as though the redirect had not occurred.
Select a status code that matches the move
A redirect status affects whether the move is treated as temporary or permanent and how the request method is handled. PHP’s default for a Location: header is 302 when no relevant status has already been set.
Rank #2
| Status | Use | Request-method behavior |
|---|---|---|
| 301 | Permanent move | Clients may change a POST to GET. RFC 7231 describes 301 as cacheable by default, so it is a poor choice for a temporary test. |
| 302 | Temporary move; also PHP’s usual default for Location: |
Clients may change a POST to GET. |
| 303 | Direct the client to retrieve another resource | The follow-up request uses GET. |
| 307 | Temporary move when the request method should be preserved | Preserves the method. |
| 308 | Permanent move when the request method should be preserved | Preserves the method. |
These distinctions follow the HTTP semantics described in IETF RFC 7231. Use a permanent response only when the move is intended to last. If the endpoint accepts POST or another non-GET method, choose a status with the required behavior and test how the client follows it.
Keep redirect destinations safe
Do not build a general-purpose redirect endpoint that blindly sends visitors to a URL supplied in a query parameter or other untrusted input. An attacker can use that behavior to make a trusted site send visitors to an attacker-controlled destination—an open redirect. Apache explicitly warns about unvalidated redirect targets in its mod_rewrite security considerations.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall- Prefer a fixed mapping from old paths to approved destinations.
- If destinations must be dynamic, validate them against a strict allowlist; do not treat arbitrary hostnames as safe.
- Decide explicitly whether the destination needs the original query string. Apache rewrite rules can preserve, append, or discard query strings, so verify the selected behavior rather than assuming parameters will carry over.
Handle HTTP-to-HTTPS redirects behind a proxy
If Apache itself terminates TLS, the request’s HTTPS state can inform an HTTP-to-HTTPS redirect. If TLS terminates at a load balancer or another upstream proxy, Apache may see an unencrypted connection even when the visitor connected over HTTPS. In that setup, a check such as %{HTTPS} on the backend may not represent the original client connection.
Apache’s guidance is to trust a forwarded-protocol header such as X-Forwarded-Proto only when the upstream proxy is controlled and overwrites the header. Otherwise, a client may forge it. For the Apache configuration details, see Redirecting and remapping with mod_rewrite. Apache documents a Redirect in a dedicated HTTP virtual host as an option for a straightforward HTTP-to-HTTPS redirect.
Quick Recap
Rank #4
Verify the redirect before relying on it
- Request the old URL and inspect the first response in a browser’s network panel or an HTTP client. Confirm the status code and
Locationheader. - Check that the target has the intended path and scheme, and confirm whether the query string is preserved, changed, or discarded as intended.
- Follow the redirect and verify that the final response is the expected resource. Point old URLs directly to their final destinations where practical to avoid unnecessary chains; check that rules do not send requests in a loop.
- If the endpoint accepts POST and method preservation matters, test with a POST request and confirm the behavior at the destination.
- If any part of the destination comes from user input, try an external hostname and verify that it is rejected unless explicitly allowlisted.
- For PHP, confirm no output precedes
header()and thatexitprevents later application code from running.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

