HTTPS

HTTPS is HTTP over TLS. For SEO, it is a lightweight ranking signal since 2014 and a clear trust cue. A small site should run 100 percent over HTTPS and redirect the rest cleanly.

By , founder of Porteur · Updated 14 September 2026 · Markdown

What HTTPS means for SEO

Google announced HTTPS as a lightweight ranking signal in August 2014. Chrome has marked HTTP pages as Not secure since July 2018, and browsers now default to HTTPS. Users expect the lock. Search expects the secure version to be canonical.

On a small site, the gains are simple: fewer browser warnings, higher user trust, and fewer indexing quirks. You will not jump rankings on HTTPS alone, but you remove friction that costs clicks and links.

How to check your setup

  1. Open a known HTTP URL

    Type http://yourproduct.com/pricing. It should 301 once to https://yourproduct.com/pricing, not via www or a slash hop first.

  2. Check canonicals and sitemap

    View source on a few pages. The rel=canonical must point to the HTTPS URL. Your XML sitemap should list only HTTPS URLs.

  3. Test mixed content

    Load https://yourproduct.com in a fresh browser tab and check the console for blocked HTTP images, scripts or fonts. Fix to HTTPS or host locally.

  4. Verify in Search Console

    Add your site as a Domain property so both protocols are covered at once. Use the Sitemaps report to resubmit the HTTPS sitemap.

  5. Spot stray links

    Search your codebase and CMS for “http://yourproduct.com”. Update internal links, Open Graph tags and RSS feeds to HTTPS.

The migration checklist

Certificates are free. Use Let’s Encrypt or your CDN’s certificate. Enable TLS on all hosts that serve your domain, including www and any subdomains you use.

  • Force a 301 from HTTP to HTTPS in one hop on every host.
  • Keep the same paths and query strings. Do not change URLs during the switch.
  • Set rel=canonical to the HTTPS URL on every page.
  • List only HTTPS URLs in your XML sitemap and resubmit it.
  • Update hreflang, Open Graph and structured data to reference HTTPS.
  • Rewrite absolute internal links to HTTPS. Relative links are fine.
  • Purge caches and warm the CDN on key pages like /, /pricing and /guides/getting-started.

A fixed page looks like this: http://yourproduct.com/pricing 301 → https://yourproduct.com/pricing. The page source rel=canonical is https://yourproduct.com/pricing and every resource loads over HTTPS.

Common traps and how to fix them

  • Mixed content: an HTTPS page loads an image, script or font over HTTP. Update the URL to HTTPS or serve the file from your domain.
  • Redirect loops: both HTTP and HTTPS redirect to each other. Fix rules so only HTTP redirects to HTTPS, never the other way.
  • Redirect chains: http → http www → https www. Collapse to a single 301 hop.
  • Stale canonicals: pages still declare an HTTP canonical. Update templates so it is always the HTTPS URL.
  • Old sitemaps: an HTTP sitemap still listed or submitted. Remove it, submit the HTTPS sitemap only.
  • Subdomains forgotten: blog.yourproduct.com still on HTTP. Issue a certificate and apply the same rules there.

When to add HSTS

HTTP Strict Transport Security tells browsers to always use HTTPS for your domain. It reduces downgrade attacks and removes a first hop from HTTP. Set a short max‑age first, then raise it once you are confident.

Only enable HSTS after every page and subdomain you serve is stable on HTTPS and redirecting correctly. Consider the preload list later, as it is hard to roll back.

Questions

Sources

Check my site, free

Run your URL in Porteur’s free check to see if your pages redirect in one hop to HTTPS, your sitemap lists HTTPS URLs only, and mixed content is flagged.

  • Free check, no card
  • Read-only, your own accounts
  • Readable by your agent

Read next