If the forward happens at the HTTP level, users visiting can still be redirected to another domain before encryption is enforced. However, if someone accesses, modern browsers will try to establish a secure connection first, and a missing or invalid certificate may trigger a warning or block the request before the redirect occurs. This makes the experience inconsistent. Observing access logs and failed handshake patterns helps reveal where users drop off or never reach the target site.