Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To redirect a browser in PHP, send a Location header before any page output, then stop the script with exit. Choose the HTTP status to match whether the destination is temporary or permanent and whether the request method must be preserved.

Send a basic PHP redirect

Use PHP’s header() function to send the destination, then call exit so the script does not continue processing the original page:

<?php
header('Location: /new-page.php');
exit;

The destination can be a path on your site, such as /new-page.php, or a complete URL. PHP normally sends a 302 status with a Location header unless a 201 or 3xx status has already been set. You can specify the status explicitly as the third argument to header(). See the PHP header() manual.

Choose the right redirect status

Use a permanent status only when the resource has genuinely moved for good; permanent redirects may be cached. For a temporary redirect, choose based on what should happen to the request method. RFC 9110 defines the behavior of these status codes:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Status Use Request-method behavior
301 Permanent move A client may change POST to GET.
302 Temporary move A client may change POST to GET.
303 Direct the client to another resource The other resource is retrieved with GET or HEAD.
307 Temporary move The client must not change the request method.
308 Permanent move Method-preserving permanent redirect.

For example, make a temporary redirect explicit with header('Location: /new-page.php', true, 302);. A 303 is useful when a client should retrieve the destination with GET or HEAD after the redirect. Use 307 or 308 when the original method must be preserved. The exact behavior matters particularly for requests such as POST; do not assume every client or method behaves identically beyond the rules for the chosen status. See RFC 9110, HTTP Semantics.

Fix “headers already sent”

PHP must send response headers before it sends the response body. HTML, whitespace outside PHP tags, output from an included file, or a byte-order mark can start the body and make a later redirect fail. The PHP manual explains this ordering requirement in its header() documentation.

To identify where output began, check the return value of headers_sent() and request its optional file and line details:

<?php
if (headers_sent($file, $line)) {
    echo "Headers already sent in $file on line $line";
    exit;
}

header('Location: /new-page.php', true, 302);
exit;

If it returns true, the supplied variables identify the file and line where output started. In some cases, such as output originating before the script, the filename may be empty. See the headers_sent() manual. Output buffering can defer output, but it is usually better to fix the ordering problem rather than rely on buffering to hide it.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Prevent open redirects

Do not let untrusted input set the destination directly. This unsafe pattern allows a query parameter to control the Location header:

<?php
$target = $_GET['url'];
header('Location: ' . $target);
exit;

An attacker can use a trusted-domain link that sends visitors to an attacker-controlled site, making the link useful for phishing. Prefer a fixed destination or map a short identifier to a destination defined by your application:

<?php
$destinations = [
    'account' => '/account.php',
    'help' => '/help.php',
];

$key = $_GET['to'] ?? '';
$target = $destinations[$key] ?? '/';

header('Location: ' . $target, true, 302);
exit;

If users genuinely need to choose among destinations, validate the choice against a strict allow-list, and confirm it is appropriate for the user and action. OWASP recommends allow-listing rather than deny-listing. See the OWASP Unvalidated Redirects and Forwards Cheat Sheet.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.