How this was measured
On 2026-09-30 we requested four entry URLs for each of the same 78 hand-picked domains our other surveys use — news, commerce, SaaS, developer tooling, social, streaming, reference, SEO, education, finance, cloud, local and government. The four entries were http://domain/, https://domain/, http://www.domain/ and https://www.domain/: 312 chain walks in total.
We did not use curl -L. We requested one hop at a time so each hop's status code and Location could be recorded separately. The reason is a measurement artefact: with -L and a header dump, a proxy's own CONNECT 200 is written into the header file alongside the real responses, and it is indistinguishable from a real 200. Walking the chain by hand avoids that entirely. Every hop was attempted directly first and then through a local proxy; 220 hops answered on the direct path, 114 needed the proxy, and one never answered at all. We recorded which path each hop used so this can be checked.
We used a survey user agent that identifies itself. 14 of the 78 domains answered with a bot wall rather than a page — those are reported as unreachable and excluded, not counted as defects.
Finding 1: 62 of 78 reach a page from the worst possible entry
http://domain/ is the entry old links arrive on, the one people type, the one a third party cites. 62 of 78 (79.5%) end at a 200. Sixteen do not, and nearly all of those are walls rather than failures: 11 answered 403 (nytimes.com, bloomberg.com, ebay.com, etsy.com, quora.com, stackoverflow.com, npmjs.com, searchengineland.com, coinbase.com, doordash.com, yelp.com), 2 answered 202 (amazon.com and booking.com, both challenge pages), one answered 406 (uber.com) and 2 answered 503 (bbc.com and nih.gov).
Four domains answered the bare HTTP entry without redirecting at all. archive.org returned 200 over plain HTTP. bbc.com and nih.gov returned 503 — they refuse HTTP outright, which is a defensible choice. searchengineland.com returned 403.
Finding 2: two hops is the most common answer, and 28 of them are avoidable
Hop counts from http://domain/: 32 take one hop (41.0%), 37 take two (47.4%) and 5 take three (6.4%). One hop is not the norm here; two is.
The shapes explain why. 28 domains go http://domain → https://domain → https://www.domain — the scheme upgrade and the host canonicalisation are two separate redirects. 16 collapse both into one hop (http://domain → https://www.domain). 15 do the scheme only and stop at the bare domain, which is their canonical form. So 28 of the 37 two-hop sites spend two round trips doing what the other 16 do in one.
The usual cause is two layers that do not know about each other: an edge or load balancer that upgrades HTTP to HTTPS, and an application that then adds www. Neither is wrong alone. Together they turn every first visit into two requests before any content arrives.
The five three-hop chains, verbatim:
theguardian.com: http://theguardian.com/ → https://theguardian.com/ → https://www.theguardian.com/ → /international.
notion.so: → https://notion.so/ → https://www.notion.so/ → https://www.notion.com/ — a domain migration stacked on top of the normalisation.
netflix.com: → https://netflix.com/ → https://www.netflix.com/ → https://www.netflix.com/hk-en/.
paypal.com: → https://paypal.com/ → https://www.paypal.com/ → https://www.paypal.com/cn/home.
cdc.gov: → https://cdc.gov/ → https://www.cdc.gov/ → /index.html. Three permanent redirects to land on a filename.
Finding 3: 14 sites use a temporary redirect for something permanent
Across all 312 walks we saw 301 ×245, 302 ×36, 308 ×16 and 307 ×14. 14 domains used 302 or 307 somewhere in the chain that ends at their own homepage: theguardian.com, cnn.com, notion.so, linkedin.com, nodejs.org, go.dev, developer.mozilla.org, netflix.com, mozilla.org, mit.edu, stripe.com, paypal.com, coinbase.com and doordash.com.
Four use it on the very first hop off HTTP: go.dev (302), mozilla.org (302), mit.edu (302) and doordash.com (302). mit.edu's first hop is http://mit.edu/ → http://web.mit.edu/, a temporary code on a host mapping that has been stable for years.
This matters because 301 and 308 tell a crawler to consolidate signals onto the target and update its index, while 302 and 307 tell it to keep the original. Reaching for the temporary pair during canonicalisation is a way of asking Google to remember the URL you just said you did not want.
Two details worth keeping. mozilla.org's first hop redirects to https://mozilla.org:443/ — an explicit default port, valid and mildly unusual. pinterest.com uses 308 twice, and vercel.com and khanacademy.org each use a single 308 to upgrade the scheme; 308 is 301's method-preserving twin and is the correct choice here.
Finding 4: six sites serve two reachable homepages
56 of 78 converge — every entry that resolves ends at the same URL. 7 do not, and one of those is our own artefact, so six are real:
bbc.com: https://bbc.com and https://www.bbc.com both answer 200 and neither redirects to the other. Plain HTTP returns 503, so at least the scheme is settled.
go.dev: https://go.dev and https://www.go.dev both answer 200.
developer.mozilla.org: the bare host redirects to /en-US/, while https://www.developer.mozilla.org answers 200 at the root.
mit.edu: http://mit.edu/ ends at https://web.mit.edu/, but http://www.mit.edu/ ends at https://www.mit.edu/. Which homepage you get depends on whether you typed www.
archive.org: all four entries answer 200. http://archive.org/ is served, and www redirects back to the bare host with a 302.
khanacademy.org: the bare domain upgrades to https://www.khanacademy.org, but http://www.khanacademy.org answers 200 in plain HTTP. Of the four combinations, www plus http is the one that was forgotten.
The seventh, paypal.com, landed on /cn/home on one path and /hk/home on the other. That is a geo redirect and an artefact of us exiting from two IP addresses, not a defect on their side.
Finding 5: eight homepages are not at /
Eight domains end their chain on a path other than the root: theguardian.com/international, nodejs.org/en, developer.mozilla.org/en-US/, netflix.com/hk-en/, stripe.com/cn, paypal.com/cn/home, squareup.com/us/en and cdc.gov/index.html.
Four of those are geography — we fetched from a Chinese IP address, and Stripe, PayPal, Netflix and Square each answered with the edition they serve from there. Those redirects are doing their job; the consequence is that the URL in your sitemap is not the URL a crawler somewhere else receives. One of our sitemap findings is the same effect seen from the other end.
Two are language negotiation (nodejs.org/en, MDN's /en-US/). One is an edition router (the Guardian). One, cdc.gov, redirects its root to /index.html — the homepage's address is a filename.
Seven also end on a different host from the one requested: cnn.com → edition.cnn.com, gitlab.com → about.gitlab.com, notion.so → www.notion.com, zoom.us → www.zoom.com, spotify.com → open.spotify.com, mit.edu → web.mit.edu and linkedin.com → www.linkedin.cn. Two are domain migrations (Notion, Zoom), one is geography (LinkedIn), and the rest are structural.
Finding 6: HSTS is on half the sample, preload on a third
39 of 78 send Strict-Transport-Security on their final HTTPS response. 25 of those include preload: Shopify, Atlassian, Slack, Notion, Figma, Asana, Trello, python.org, nodejs.org, go.dev, w3.org, Ahrefs, Semrush, Yoast, Search Engine Journal, Stanford, Coursera, Stripe, PayPal, Square, Vercel, Netlify, Airbnb, cdc.gov and who.int.
That leaves 39 sending no HSTS at all, which is why the scheme hop has to exist for them: without it, a browser's first request to a typed domain is still an HTTP request. With it — and especially with preload — the browser upgrades before the request leaves, and the first hop disappears for every visit after the first.
What to do with this
Count your own hops. Run curl -sIL http://yourdomain/ and count the HTTP/ lines. Two is the most common answer in this sample and one is achievable. If you see scheme and host handled separately, move both into a single rule at whichever layer is outermost.
Use 308 or 301 for canonicalisation, never 302 or 307. Fourteen sites here use the temporary pair on a redirect that will not change. 308 preserves the method and is the better default on modern stacks.
Choose www or bare and redirect every other form to it. The forgotten combination in this sample is almost always www plus http: Khan Academy normalises the bare domain to https plus www but serves http plus www as-is. Test all four entries, not two.
If you geo-redirect, test from more than one country. Four sites here served us an edition based on our IP. The redirect is correct, and the URL in your sitemap is still not the one most of the world sees. It is also part of why our hreflang survey found so much variation in what a homepage even is.
Decide whether a redirect or a canonical tag is the answer before reaching for either. They solve different problems: a redirect removes a URL, a canonical tag consolidates duplicates you have to keep serving. Our meta tag generator emits the tag for the second case — and if you are unsure which applies, the answer is usually that the redirect is the one you want.
Turn on HSTS last. It removes the first hop for repeat visitors and, once preloaded, for first visits too — but preload is deliberately hard to reverse, so only add it after every subdomain serves HTTPS.
Limitations
78 hand-picked well-known domains, not a random sample of the web. Categories are our own manual grouping, several contain five domains, and one site moves a rate by 20 points.
All requests came from one survey user agent on one day, over two egress IP addresses — one in China and one proxy exit. 14 domains answered with a bot wall (403, 406 or 202); those are excluded rather than counted as defects, and a browser-like user agent would have reached more of them. The geographic redirects in this data — Stripe's /cn, PayPal's /cn/home, Netflix's /hk-en/, Square's /us/en, LinkedIn's .cn — describe where we were, not what those sites do for everyone. PayPal appearing in the two-version list is an artefact of our two exits, not a finding about PayPal.
Channel is chosen per hop, so some chains switch egress partway through: 220 hops ran direct, 114 through the proxy. A geo-sensitive site can therefore show a hop that no single visitor would experience.
We counted hops, not latency. A three-hop chain inside one CDN is often cheaper than a single cross-origin redirect, and we did not measure TTFB or connection reuse. Hop count stands in for wasted round trips; it is not a measurement of how slow anything is.
We did not check what gets indexed. A redirect does not guarantee consolidation, and we did not read the canonical tag at the destination — several of these domains redirect to a URL that then declares something different in our canonical survey. Whether the homepage that ranks is the one at the end of the chain is a different question from the one answered here.
We followed up to eight hops and stopped on a loop or an unresolvable Location. No chain in this sample hit either limit.
Reproduce it
The script and the shared domain list ship with this site. node scripts/survey-redirects.mjs walks all four entries for all 78 domains and stores every hop; --report re-derives every number from stored data without touching the network; --evidence prints the status and Location of every hop for manual checking, which is how each chain quoted above was verified. Our robots.txt, canonical, hreflang, AI crawler and llms.txt surveys use the same domain list from other angles.