
Table of Contents
What is .htaccess?
The .htaccess file (Hypertext Access) is a directory-level configuration file for Apache HTTP Server. It lets you control web server behavior without editing the main httpd.conf config file, which requires root access.
On AsiaGB DirectAdmin Hosting, Apache is configured with AllowOverride All enabled by default, meaning .htaccess works immediately for every site — no support ticket needed.
💡 The filename starts with a dot, making it a "hidden file" on Linux systems. Enable Show Hidden Files in DirectAdmin's File Manager to see it.
Why use .htaccess?
.htaccess handles tasks that can't be done through PHP or HTML alone:
| Task | .htaccess Directive | Why use .htaccess |
|---|---|---|
| Redirect old → new URL | RewriteRule / Redirect | Server-level, runs before PHP |
| Force HTTPS | RewriteRule HTTPS | Secure, no code changes needed |
| Password-protect a directory | AuthType Basic | Faster than PHP session auth |
| Custom 404/500 error pages | ErrorDocument | Applies to all URLs consistently |
| Block IP or User-Agent | Deny from | Blocks before PHP processes request |
| Set Cache-Control headers | Header set | Controls browser caching precisely |
Create & Edit .htaccess on DirectAdmin
There are two main ways to create or edit .htaccess:
Method 1 — Via DirectAdmin File Manager
- Log in to DirectAdmin → select File Manager
- Navigate to
public_html/ - Click "New File" → name it
.htaccess(with a leading dot) - Click Edit, paste your directives → Save
📂 If you can't see .htaccess in File Manager, click "Show Hidden Files" in the top-right corner.
Method 2 — Via FTP
- Open your FTP client (e.g. FileZilla) → connect with credentials from DirectAdmin
- Navigate to
public_html/ - Create
.htaccesslocally and upload it to the server
⚠️ Always back up before editing! A syntax error in .htaccess causes an immediate 500 Error. Download a copy first.
URL Redirects with .htaccess
URL redirecting is the most common .htaccess use case — especially for domain migrations, HTTPS enforcement and www/non-www canonicalization.
Force HTTPS (HTTP → HTTPS Redirect)
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Single Page Redirect (301 Permanent)
Redirect 301 /old-page.html https://yourdomain.com/new-page.html
Redirect www → non-www
RewriteEngine On
RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
RewriteRule ^ https://%1%{REQUEST_URI} [R=301,L]
Custom 404 Error Page
ErrorDocument 404 /404.html
🔎 301 vs 302: Use 301 (Permanent) when a URL has moved permanently — Google transfers PageRank to the new URL. Use 302 (Temporary) only for short-term redirects.
Password Protection — Lock a Directory
To restrict access to directories like /admin or /staging with a username and password:
Step 1 — Create .htpasswd file
Create the .htpasswd file outside public_html, e.g. at /home/username/.htpasswd, using an online htpasswd generator or DirectAdmin Terminal:
htpasswd -c /home/username/.htpasswd myusername
Step 2 — Add to .htaccess in the directory to protect
AuthType Basic AuthName "Protected Area" AuthUserFile /home/username/.htpasswd Require valid-user
Custom Error Pages
Instead of showing Apache's plain error pages, create friendly branded pages:
ErrorDocument 404 /404.html ErrorDocument 403 /403.html ErrorDocument 500 /500.html
Create 404.html in your website root (public_html/404.html) with navigation links and a search form to reduce bounce rate.
IP Blocking & Access Control
If your site is being spammed or attacked from specific IPs, block them via .htaccess:
Block specific IPs
Order allow,deny Allow from all Deny from 123.456.789.0 Deny from 192.168.1.0/24
Block bad bots by User-Agent
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} (BadBot|EvilScraper|SpamBot) [NC]
RewriteRule .* - [F,L]
Block direct access to sensitive files
<FilesMatch "\.(env|log|sql|bak)$"> Order allow,deny Deny from all </FilesMatch>
🔒 Always block direct access to .env, .log and .sql files — they may contain database credentials that could be exposed publicly.
.htaccess and SEO
.htaccess has direct SEO impact across four key areas:
| Setting | SEO Impact |
|---|---|
| 301 Redirect | Transfers link equity to new URL, prevents duplicate content |
| HTTPS Redirect | Google gives ranking preference to HTTPS; builds trust |
| Custom 404 Page | Reduces bounce rate; Google sees proper 404 response code |
| Cache Headers | Faster load = better Core Web Vitals = higher rankings |
Example: Canonical URL Enforcement (www → non-www + HTTPS)
RewriteEngine On
# Redirect www to non-www
RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
RewriteRule ^ https://%1%{REQUEST_URI} [R=301,L]
# Redirect HTTP to HTTPS
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Cache & Compression Settings
Fast-loading websites rank better and convert better. Browser caching and Gzip compression via .htaccess make a significant difference:
Browser Caching with mod_expires
<IfModule mod_expires.c> ExpiresActive On ExpiresByType image/jpg "access plus 1 year" ExpiresByType image/jpeg "access plus 1 year" ExpiresByType image/webp "access plus 1 year" ExpiresByType image/png "access plus 1 year" ExpiresByType text/css "access plus 1 month" ExpiresByType application/javascript "access plus 1 month" ExpiresByType text/html "access plus 1 hour" </IfModule>
Gzip Compression with mod_deflate
<IfModule mod_deflate.c> AddOutputFilterByType DEFLATE text/html text/plain text/css AddOutputFilterByType DEFLATE application/javascript application/json AddOutputFilterByType DEFLATE image/svg+xml </IfModule>
⚡ Enabling Gzip compression can reduce HTML/CSS/JS file sizes by 60–70%, noticeably improving load times especially on slow connections.
Frequently Asked Questions
public_html/ (your website root). Open File Manager in DirectAdmin, enable Show Hidden Files to see it.Summary — Start Using .htaccess on DirectAdmin Today
.htaccess is one of the most powerful tools available to every hosting account. From redirecting old URLs after a domain change, enforcing HTTPS, password-protecting sensitive directories, to boosting site speed with cache headers — it handles all of this at the server level.
On AsiaGB DirectAdmin Hosting, mod_rewrite and mod_expires are enabled by default, so every .htaccess directive works immediately without any additional configuration.
Looking for hosting with full .htaccess support and an easy-to-use DirectAdmin panel? AsiaGB plans start at 500 THB/month with SSD storage and 99% Uptime.
Get Hosting with Full .htaccess Support
DirectAdmin Hosting · SSD Storage · 99% Uptime · twice-monthly automated backups
View Hosting Plans