HTTPS
HTTPS is HTTP over TLS. For SEO, it is a lightweight ranking signal since 2014 and a clear trust cue. A small site should run 100 percent over HTTPS and redirect the rest cleanly.
By Théophile Louvart, founder of Porteur · Updated 14 September 2026 · Markdown
What HTTPS means for SEO
Google announced HTTPS as a lightweight ranking signal in August 2014. Chrome has marked HTTP pages as Not secure since July 2018, and browsers now default to HTTPS. Users expect the lock. Search expects the secure version to be canonical.
On a small site, the gains are simple: fewer browser warnings, higher user trust, and fewer indexing quirks. You will not jump rankings on HTTPS alone, but you remove friction that costs clicks and links.
How to check your setup
Open a known HTTP URL
Type http://yourproduct.com/pricing. It should 301 once to https://yourproduct.com/pricing, not via www or a slash hop first.
Check canonicals and sitemap
View source on a few pages. The rel=canonical must point to the HTTPS URL. Your XML sitemap should list only HTTPS URLs.
Test mixed content
Load https://yourproduct.com in a fresh browser tab and check the console for blocked HTTP images, scripts or fonts. Fix to HTTPS or host locally.
Verify in Search Console
Add your site as a Domain property so both protocols are covered at once. Use the Sitemaps report to resubmit the HTTPS sitemap.
Spot stray links
Search your codebase and CMS for “http://yourproduct.com”. Update internal links, Open Graph tags and RSS feeds to HTTPS.
The migration checklist
Certificates are free. Use Let’s Encrypt or your CDN’s certificate. Enable TLS on all hosts that serve your domain, including www and any subdomains you use.
- Force a 301 from HTTP to HTTPS in one hop on every host.
- Keep the same paths and query strings. Do not change URLs during the switch.
- Set rel=canonical to the HTTPS URL on every page.
- List only HTTPS URLs in your XML sitemap and resubmit it.
- Update hreflang, Open Graph and structured data to reference HTTPS.
- Rewrite absolute internal links to HTTPS. Relative links are fine.
- Purge caches and warm the CDN on key pages like /, /pricing and /guides/getting-started.
A fixed page looks like this: http://yourproduct.com/pricing 301 → https://yourproduct.com/pricing. The page source rel=canonical is https://yourproduct.com/pricing and every resource loads over HTTPS.
Common traps and how to fix them
- Mixed content: an HTTPS page loads an image, script or font over HTTP. Update the URL to HTTPS or serve the file from your domain.
- Redirect loops: both HTTP and HTTPS redirect to each other. Fix rules so only HTTP redirects to HTTPS, never the other way.
- Redirect chains: http → http www → https www. Collapse to a single 301 hop.
- Stale canonicals: pages still declare an HTTP canonical. Update templates so it is always the HTTPS URL.
- Old sitemaps: an HTTP sitemap still listed or submitted. Remove it, submit the HTTPS sitemap only.
- Subdomains forgotten: blog.yourproduct.com still on HTTP. Issue a certificate and apply the same rules there.
When to add HSTS
HTTP Strict Transport Security tells browsers to always use HTTPS for your domain. It reduces downgrade attacks and removes a first hop from HTTP. Set a short max‑age first, then raise it once you are confident.
Only enable HSTS after every page and subdomain you serve is stable on HTTPS and redirecting correctly. Consider the preload list later, as it is hard to roll back.
Questions
A little. As of 2014 it is a lightweight signal. The real gains are trust, no browser warnings and cleaner indexing. You still need good content and speed.
Keep URLs the same and 301 every HTTP URL to its HTTPS twin in one hop. Update canonicals, sitemaps and internal links to HTTPS. Verify a Domain property in Search Console and submit the HTTPS sitemap.
It is when an HTTPS page loads assets over HTTP. Browsers block or warn on these. Open the console on a few key pages and fix each URL to HTTPS or host the file yourself.
Yes, once everything works on HTTPS. Start with a short max‑age so you can roll back if needed, then extend it and consider preloading when stable.
Not urgently if your redirects are clean. A one‑hop 301 passes users and signals. Update important links you control, like profiles and directory listings.
Yes. The rel=canonical should point to the HTTPS version of the page. This helps Google index the secure URL and avoids duplicate protocol versions.
Sources
Check my site, free
Run your URL in Porteur’s free check to see if your pages redirect in one hop to HTTPS, your sitemap lists HTTPS URLs only, and mixed content is flagged.
- Free check, no card
- Read-only, your own accounts
- Readable by your agent
Read next
- GlossaryCanonical URL
- GuideAlternate page with proper canonical tag: what Search Console means
- GuideThe Sitemaps report: what Success, Has errors and Couldn’t fetch mean
- GuideHow to verify a site in Google Search Console, and which property to pick
- Glossary301 redirect
- GuideTechnical SEO checklist for a small site
- Free toolRedirect checker
- Glossary302 redirect