HTTPS (HyperText Transfer Protocol Secure) encrypts the data exchanged between a visitor’s browser and your server, protecting information like passwords, payment details, and browsing activity from interception. Google confirmed HTTPS as a lightweight ranking signal back in 2014, and it remains a baseline expectation today — browsers actively flag HTTP-only sites as “Not Secure.”
Why it matters beyond rankings: Modern browsers display clear warnings on non-HTTPS sites, which damages user trust and increases bounce rates regardless of any direct SEO impact. Certain modern web features (like some JavaScript APIs) also require a secure context to function at all.
Migrating from HTTP to HTTPS correctly: 1. Obtain an SSL/TLS certificate (many hosts offer free certificates via Let’s Encrypt). 2. Set up 301 redirects from every HTTP URL to its HTTPS equivalent. 3. Update internal links, canonical tags, and your sitemap to reference HTTPS URLs directly, rather than relying on redirects. 4. Update your Google Search Console property to the HTTPS version and resubmit your sitemap. 5. Check for “mixed content” warnings, where HTTPS pages still load some resources (images, scripts) over HTTP.
Common mistake: Migrating to HTTPS without updating internal links means every internal click triggers an unnecessary redirect, slightly slowing down both users and crawlers.
Choosing the right certificate
For SEO purposes, every valid certificate is equal. Google does not rank sites higher for a paid or extended-validation (EV) certificate. Choose based on your needs:
- Domain Validated (DV): free from Let's Encrypt or included with most hosts and CDNs. Enough for blogs, business sites and most stores.
- Organisation Validated (OV): confirms the company behind the domain. Sometimes required by enterprise or banking partners.
- Wildcard certificates: cover all subdomains (
*.example.com), useful if you run many subdomains.
Whatever you choose, set up automatic renewal. An expired certificate shows a full-page browser warning that stops almost every visitor.
Fixing mixed content
Mixed content happens when an HTTPS page loads images, scripts or stylesheets over HTTP. Browsers block insecure scripts entirely and may show a warning for images. To find it:
- Open the page in Chrome, press F12 and check the Console for "Mixed Content" messages.
- Crawl the site with a tool such as Screaming Frog and filter for insecure (http://) resources.
- Search your database for hard-coded
http://yourdomain.comlinks, which are common in older WordPress posts, and replace them.
Add HSTS once everything works
HTTP Strict Transport Security (HSTS) tells browsers to always use HTTPS for your domain, even if someone types http://. This removes one redirect for returning visitors and protects against downgrade attacks. Add the header Strict-Transport-Security: max-age=31536000; includeSubDomains only after you have confirmed every subdomain works on HTTPS, because browsers will refuse HTTP for the whole period.
HTTPS migration checklist
- Crawl the HTTP site and save the full URL list before you start.
- Use one-to-one 301 redirects (each HTTP URL to its HTTPS equivalent), not a redirect of everything to the homepage.
- Avoid redirect chains such as http://example.com → http://www.example.com → https://www.example.com. Redirect straight to the final URL.
- Update canonical tags, hreflang tags, the XML sitemap and the Sitemap line in robots.txt.
- Update links you control: social profiles, Google Business Profile, email signatures and ad destination URLs.
- Monitor the Page indexing report in Search Console for a few weeks. Indexed HTTPS pages should rise as HTTP pages fall.
Security beyond HTTPS
HTTPS protects data in transit, but a hacked site can still be removed from search or flagged with a "This site may be hacked" warning. Keep your CMS, themes and plugins updated, use strong admin passwords with two-factor login, and check the Security issues report in Search Console regularly. Security problems found there should be fixed before any other SEO work.
