Moving from HTTP to HTTPS: the checklist that keeps rankings

You are switching your site to HTTPS and want to keep your rankings. This checklist gives you the exact steps: redirects in one hop, updates across tags and files, and the checks to run before and after. It is written for founders who ship their own sites.

By , founder of Porteur · Updated 14 September 2026 · Markdown

Plan the move and build the redirect map

Treat HTTP to HTTPS as a site move. Rankings hold when every old URL maps to its HTTPS twin in one hop. Plan before you touch production.

  1. Crawl the current HTTP site

    Export every live URL. Use your crawler, your XML sitemap, and Search Console indexed pages. Combine and de-duplicate into one list.

  2. Create a two-column redirect map

    Old URL in column A, new HTTPS URL in column B. For most rows this is a straight protocol swap. Example: http://yourproduct.com/pricing to https://yourproduct.com/pricing.

  3. Decide your host and slashes

    Pick www or non-www. Pick trailing slash or not. Google treats each as different. Make the map reflect your choice across every path.

  4. Spot edge cases

    Handle 404s, 410s, parameter patterns, uppercase or mixed-case URLs, and legacy subdomains. Put a precise target or a gone status for each.

Get and install the certificate

Use a valid TLS certificate, covering your chosen host and any extra hostnames you serve. Force TLS 1.2 or newer. Test expiry alerts.

  • Choose the exact host you will serve: https://yourproduct.com or https://www.yourproduct.com
  • Cover all needed SANs, for example api.yourproduct.com if you serve it under the same cert
  • Install the full chain on your CDN or web server
  • Set auto renew and monitoring for expiry

If you use a CDN or managed platform, follow their HTTPS guide. Do not enable any redirect toggle until your 301 rules are ready and tested.

Configure one-hop 301 redirects at the edge

Apply the map at the edge or web server. 301 every HTTP URL to the exact HTTPS twin in one hop. Redirect the alternate host and slash variant too.

  • HTTP to HTTPS on the canonical host, one hop
  • Non-canonical host to canonical host with HTTPS, one hop
  • Slash variant to chosen slash form with HTTPS, one hop
# nginx map example
map $request_uri $target_suffix {
    default $request_uri;
}
server {
    listen 80;
    server_name yourproduct.com www.yourproduct.com;
    return 301 https://yourproduct.com$target_suffix;
}
// next.config.js redirects example
module.exports = {
  trailingSlash: false,
  async redirects() {
    return [
      // http -> https handled at proxy/CDN
      { source: '/pricing/', destination: '/pricing', permanent: true },
      // legacy path example
      { source: '/old-guide', destination: '/guides/getting-started', permanent: true },
    ]
  },
}

Test the rules in staging with the full map. Use a script to request every old URL, follow redirects, and log the final status and hop count. The final must be 200. The hop count must be one.

Update canonicals, sitemaps, hreflang and structured data

Google reads your tags and files as hints. Update them to HTTPS on launch, or you send mixed signals and slow the move.

  • Canonical tags: point to the HTTPS canonical on each page
  • Hreflang: every alternate URL uses HTTPS and matches canonical language targets
  • XML sitemaps: list only HTTPS URLs, keep the old HTTP sitemap live for a while so Google recrawls and sees the 301s
  • Structured data: fix any URL fields to HTTPS in JSON-LD, including Organization, Breadcrumb, Article or Product markup
  • Open Graph and Twitter tags: set og:url and similar to HTTPS
// Next.js App Router example
export async function generateMetadata() {
  const base = new URL('https://yourproduct.com');
  return {
    metadataBase: base,
    alternates: { canonical: '/pricing' },
    openGraph: { url: '/pricing', title: 'Pricing' },
  };
}

// app/sitemap.ts lists HTTPS URLs only
export default function sitemap() {
  return [
    { url: 'https://yourproduct.com/', lastModified: new Date() },
    { url: 'https://yourproduct.com/pricing', lastModified: new Date() },
  ];
}

A fixed page has rel=canonical set to its HTTPS self, shows HTTPS in JSON-LD and meta tags, and appears once in the sitemap with the HTTPS URL.

Consider HSTS and the preload list

HTTP Strict Transport Security tells browsers to use HTTPS for your host after first contact. Preload enforces this from the first visit. Apply this only when all redirects and subdomains are ready.

  • Add the HSTS header on the canonical host: max-age, includeSubDomains if you can support it, and preload if you meet the preload rules
  • Test on a subset of traffic before adding includeSubDomains or preload
  • Once preloaded, removal takes time, so be sure before you submit

Use a long max-age, for example a year. That is typical, not measured here.

# HSTS header example
Strict-Transport-Security: max-age=<long-duration>; includeSubDomains; preload

Set up Search Console for HTTPS and submit sitemaps

Verify the HTTPS property. Add a Domain property so it covers both hosts. Submit your new HTTPS sitemap and keep the old HTTP sitemap listed for a while so Google recrawls the old URLs and finds the 301s.

  • Verify https://yourproduct.com and the Domain property for your root domain
  • Submit /sitemap.xml with HTTPS URLs in the Sitemaps report
  • Use the URL Inspection tool on a few key pages to confirm the canonical is HTTPS
  • If you also change domains, use the Change of address tool once 301s are live and both properties are verified. This is not required for HTTPS only.

Launch checklist for the switchover day

Pick a low traffic window. Deploy in one release. Keep the old property and logs open while you switch.

  1. Deploy redirects

    Enable the 301 rules at the edge. Confirm that HTTP on both www and non-www map in one hop to the chosen HTTPS host and slash form.

  2. Deploy tag and file updates

    Publish sitemap with HTTPS URLs, canonicals, hreflang, JSON-LD, and robots.txt links to HTTPS sitemaps if you reference them.

  3. Smoke test key paths

    Home, /pricing, /signup, /blog, and your top landing pages. Check cookies, sign in and payments over HTTPS.

  4. Run the redirect test suite

    Hit the full redirect map. Fail if any target ends 200 through more than one hop or ends 3xx, 4xx or 5xx.

  5. Submit sitemap and spot check in Search Console

    Resubmit the HTTPS sitemap. Inspect a few URLs. Check that Google sees the HTTPS canonical.

Monitor and fix after the move

Expect fluctuation for some weeks. Watch redirects, indexation and user behaviour. Fix what you see in logs and reports fast.

  • Run a redirect checker across the map daily for the first week, then weekly for a month
  • Check the Search Console Performance report for the HTTPS property. Compare clicks and impressions to the old property
  • Use the Indexing reports to find Page with redirect, Soft 404 and Duplicate without user-selected canonical errors and fix the cause
  • Keep the HTTP property verified and its sitemap listed for at least a few months
  • Keep the 301s live for as long as possible, at least a year, preferably permanently

A fixed site shows stable one-hop redirects, growing HTTPS impressions, and fewer HTTP pages in the index each week.

www, trailing slash and other common traps

Google treats www and non-www as different hosts, and /page and /page/ as different URLs. Pick one for each and enforce it with 301s on every path. Keep internal links consistent. This avoids duplicate content and redirect chains.

  • www vs non-www: choose one, 301 the other, set canonicals to the chosen host, verify a Domain property
  • Trailing slash: choose a policy, 301 the other, and set Next.js trailingSlash to match your choice
  • Avoid redirect chains: map http://www to https://example in one step, not http://www to http://example to https://example
  • Parameters: decide which parameters are canonical and keep that consistent in links and sitemaps

Questions

Sources

Check my site, free

Run the free check from a URL and get three findings on your redirects, canonical signals and HTTPS coverage in about thirty seconds, no signup.

  • Free check, no card
  • Read-only, your own accounts
  • Readable by your agent

Read next