Pick one version of your domain, www or non-www, and send all traffic there with a 301 redirect. The fastest way is cPanel's Domains tool: find your domain, click Redirects, and set it to force one version. If you want more control, or you're managing a lot of rules, edit .htaccess directly through File Manager.
Either method works. The cPanel tool is faster and harder to break. Editing .htaccess is better when you're already managing other redirect rules in the same file and want everything in one place.
Using the cPanel Redirects tool
In cPanel, open Domains → Redirects. Pick the domain, choose www or non-www as the destination, and save. This writes the redirect rule for you and avoids the most common mistakes people make hand-editing .htaccess, like forgetting to escape a dot or creating a loop.
If your account uses the Meridian theme, the same setting lives under Websites & Apps → your site → Settings → Redirects.
Editing .htaccess directly
Open File Manager, navigate to your domain's document root, and edit (or create) .htaccess. To force www:
RewriteEngine On
RewriteCond %{HTTP_HOST} ^example\.com [NC]
RewriteRule ^(.*)$ https://www.example.com/$1 [L,R=301]
To force non-www instead:
RewriteEngine On
RewriteCond %{HTTP_HOST} ^www\.example\.com [NC]
RewriteRule ^(.*)$ https://example.com/$1 [L,R=301]
Replace example.com with your actual domain. Put this block near the top of .htaccess, before any WordPress-generated rewrite rules (the block between # BEGIN WordPress and # END WordPress). If your site runs on WordPress, don't add this inside that block. WordPress will overwrite it whenever permalinks are resaved.
Why 301, not 302
R=301 tells browsers and search engines the move is permanent, so they update bookmarks and search index entries to the new URL and stop crawling the old one. A 302 signals a temporary redirect, which search engines will keep re-checking. For a permanent www/non-www decision, always use 301.
Matching your SSL certificate and DNS
Before redirecting, confirm both versions of your domain actually resolve and carry a valid certificate. If you've customized DNS Zone Editor records, check that both example.com and www.example.com point to your hosting. Mismatched DNS is the usual cause of a redirect working in a browser tab but failing with a certificate warning.
Avoiding redirect loops
A loop happens when two rules point at each other, for example a www-to-non-www rule in .htaccess fighting a non-www-to-www setting in the cPanel Redirects tool. Use one method, not both. If you switch from .htaccess rules to the cPanel tool, remove the old rewrite block first. If you switch from Cloudflare CDN's settings, check the Cloudflare CDN page in the portal to make sure Always Use HTTPS isn't also redirecting the host.
Checking the result
Test with a request that shows headers, not just a browser. Browsers cache redirects and can hide a broken rule. From a terminal:
curl -I https://example.com/
Look for HTTP/2 301 (or HTTP/1.1 301) and a location header pointing at the version you chose. Test both the root domain and a few inner pages, since a rule written too narrowly sometimes only catches the homepage.
When to contact support
If the redirect loops, the certificate doesn't match after you've confirmed DNS, or you're not sure whether a rule is coming from .htaccess, the cPanel Redirects tool, or Cloudflare CDN settings, open a ticket from the portal's Support section. It goes to a real person, and they can check the live configuration on your account directly.