SSL profiles

redirect.pizza automatically installs and renews SSL certificates for your domains. This makes sure your redirects keep working over both https:// and https://, without having to manage certificates yourself.

By default, we use the tlsserver profile from Let's Encrypt. Certificates issued with this profile are valid for 45 days.

If Let's Encrypt is unavailable, rate limited or unable to issue a certificate, we can automatically fall back to ZeroSSL. Certificates issued through ZeroSSL are valid for 90 days.

Short-lived SSL certificates

Customers on the Pro plan and up can opt in to short-lived SSL certificates.

This uses the shortlived profile from Let's Encrypt. Certificates issued with this profile are valid for 160 hours, which is just over 6 days.

Short-lived certificates are renewed much more often than regular certificates. This can be useful if you want certificates with a shorter lifetime and fully rely on automatic certificate renewal.

Available short-lived modes

When enabling short-lived certificates, you can choose between two modes:

  • Preferred: redirect.pizza will try to issue a short-lived certificate first. If this fails, we will fall back to a regular certificate. This is the default and recommended option.
  • Strict: redirect.pizza will only try to issue a short-lived certificate. If that fails, we will not fall back to a regular certificate.

Which option should I choose?

For most customers who want to use short-lived certificates, we recommend using Preferred.

This gives you the benefit of short-lived certificates when issuance works as expected, while still keeping a regular SSL certificate as a fallback if the short-lived certificate cannot be issued.

Use Strict only if you specifically require short-lived certificates and do not want redirect.pizza to issue a regular certificate as fallback.

What changes when using short-lived certificates?

Your redirects keep working in the same way. The main difference is the certificate lifetime and renewal frequency.

  • Regular Let's Encrypt certificates using the tlsserver profile are valid for 45 days.
  • Short-lived certificates using the shortlived profile are valid for 160 hours.
  • Because the validity period is much shorter, redirect.pizza renews these certificates more often.

You do not need to make DNS changes or manually renew the certificate. redirect.pizza handles the SSL process automatically.

When does the new profile take effect?

When you change the SSL profile for a domain, the existing certificate is not replaced immediately. The new profile will be used the next time the certificate is renewed.

This means the currently active certificate will stay in place until its next renewal period. After that, redirect.pizza will request the new certificate using the selected SSL profile.

Need help?

Not sure which SSL profile is best for your setup? Contact support via the chat or send us an email on support@redirect.pizza. We are happy to help.

More articles

Walkthroughs
GoDaddy: Forwarding with HTTPS support
Network Solutions: Forwarding with HTTPS support
Namecheap: Forwarding with HTTPS support
Hover: Forwarding with HTTPS support
TransIP: Forwarding with HTTPS support
Cloudflare: Forwarding with HTTPS support
Amazon Route 53: Forwarding with HTTPS support
NS1: Forwarding with HTTPS support
DigitalOcean: Forwarding with HTTPS support
Google Cloud DNS: Forwarding with HTTPS support
EuroDNS: Forwarding with HTTPS support
Azure DNS: Forwarding with HTTPS support
DNS Made Easy: Forwarding with HTTPS support
Freenom: Forwarding with HTTPS support
Mijndomein: Forwarding with HTTPS support

Domain redirects delivered hassle-free

Get started right away

  • Free plan
  • No creditcard required

redirect.pizza has all your favorite ingredients

Analytics

Who is still visiting those old domains? Gain valuable insight with detailed statistics and find out where the hits are coming from.

Learn more

API

Connect your software to automatically create redirects via our API. Automation makes your life easier.

Learn more

Destination Variables

You control how we handle your destination URL. Want to include your domain extension as a query string parameter? No problem.

Learn more

Dynamic destinations

Steer your traffic to different destinations, based on rules you define.

Learn more

Path forwarding

Keep the original path and keep it in the destination for a smooth domain migration and keeping your SEO game intact.

Learn more

Query Parameter Forwarding

Forward query parameters found on the source URL to the destination.

Learn more

Multiple Redirect Types

Choose the status code that works for you. Choose 301/307 (permanent), 302/308 (temporary) or frame your destination.

Learn more

Team management

Doing things all by yourself isn't much fun. Invite your co-workers to manage the redirects and work as a team.

Learn more

Automatic DNS

Integrate directly with your DNS provider, and apply the DNS changes from one platform.

Learn more

QR code generator

Create a QR code that you can use for marketing purposes. You can change the destination anytime after printing.

Learn more

Import & Export

Manage your redirects without losing precious time. Import and export redirects in our UX-friendly interface.

Global edge network

Redirecting in a blink of an eye; processing millions of request per hour in milliseconds.

Learn more

Broken destination monitor

Automatically checking your destinations to ensure it's reachable for everyone.

Learn more

Privacy First

We're based in Europe and are fully compliant with GDPR. Privacy-first!

Learn more

Wildcard subdomains

For when your domain utilizes a lot of different subdomains. Cover all subdomains with a single redirect.

Learn more

Tags

Group your redirects by adding tags. Keep everything organized and easy to find.

Bulk actions

Want to apply the same action for multiple redirects in one go? Do yourself a favor and start using bulk actions.

Dark mode

Give your eyes some well deserved rest by using the dark mode. Sync with your system or choose manually.

HSTS

Enable HSTS (HTTP Strict Transport Security) on team or domain level for an extra layer of protection.

Learn more

Change Destination Anytime

Once you're set up, you can change the destination URL anytime you want, and see the change in real-time.

Two-Factor Authentication

Secure your account with TOTP two-factor authentication. Scan the QR code, setup your app of choice, and you're safe(er).

Learn more

IDN Support

Add international hostnames with non-Latin characters. We ❤ that.

Support

Chat away! We're happy to help set up your account and answer your questions.