Moving from HTTP to HTTPS: the checklist that keeps rankings
You are switching your site to HTTPS and want to keep your rankings. This checklist gives you the exact steps: redirects in one hop, updates across tags and files, and the checks to run before and after. It is written for founders who ship their own sites.
By Théophile Louvart, founder of Porteur · Updated 14 September 2026 · Markdown
Plan the move and build the redirect map
Treat HTTP to HTTPS as a site move. Rankings hold when every old URL maps to its HTTPS twin in one hop. Plan before you touch production.
Crawl the current HTTP site
Export every live URL. Use your crawler, your XML sitemap, and Search Console indexed pages. Combine and de-duplicate into one list.
Create a two-column redirect map
Old URL in column A, new HTTPS URL in column B. For most rows this is a straight protocol swap. Example: http://yourproduct.com/pricing to https://yourproduct.com/pricing.
Decide your host and slashes
Pick www or non-www. Pick trailing slash or not. Google treats each as different. Make the map reflect your choice across every path.
Spot edge cases
Handle 404s, 410s, parameter patterns, uppercase or mixed-case URLs, and legacy subdomains. Put a precise target or a gone status for each.
Get and install the certificate
Use a valid TLS certificate, covering your chosen host and any extra hostnames you serve. Force TLS 1.2 or newer. Test expiry alerts.
- Choose the exact host you will serve: https://yourproduct.com or https://www.yourproduct.com
- Cover all needed SANs, for example api.yourproduct.com if you serve it under the same cert
- Install the full chain on your CDN or web server
- Set auto renew and monitoring for expiry
If you use a CDN or managed platform, follow their HTTPS guide. Do not enable any redirect toggle until your 301 rules are ready and tested.
Configure one-hop 301 redirects at the edge
Apply the map at the edge or web server. 301 every HTTP URL to the exact HTTPS twin in one hop. Redirect the alternate host and slash variant too.
- HTTP to HTTPS on the canonical host, one hop
- Non-canonical host to canonical host with HTTPS, one hop
- Slash variant to chosen slash form with HTTPS, one hop
# nginx map example
map $request_uri $target_suffix {
default $request_uri;
}
server {
listen 80;
server_name yourproduct.com www.yourproduct.com;
return 301 https://yourproduct.com$target_suffix;
}
// next.config.js redirects example
module.exports = {
trailingSlash: false,
async redirects() {
return [
// http -> https handled at proxy/CDN
{ source: '/pricing/', destination: '/pricing', permanent: true },
// legacy path example
{ source: '/old-guide', destination: '/guides/getting-started', permanent: true },
]
},
}
Test the rules in staging with the full map. Use a script to request every old URL, follow redirects, and log the final status and hop count. The final must be 200. The hop count must be one.
Update canonicals, sitemaps, hreflang and structured data
Google reads your tags and files as hints. Update them to HTTPS on launch, or you send mixed signals and slow the move.
- Canonical tags: point to the HTTPS canonical on each page
- Hreflang: every alternate URL uses HTTPS and matches canonical language targets
- XML sitemaps: list only HTTPS URLs, keep the old HTTP sitemap live for a while so Google recrawls and sees the 301s
- Structured data: fix any URL fields to HTTPS in JSON-LD, including Organization, Breadcrumb, Article or Product markup
- Open Graph and Twitter tags: set og:url and similar to HTTPS
// Next.js App Router example
export async function generateMetadata() {
const base = new URL('https://yourproduct.com');
return {
metadataBase: base,
alternates: { canonical: '/pricing' },
openGraph: { url: '/pricing', title: 'Pricing' },
};
}
// app/sitemap.ts lists HTTPS URLs only
export default function sitemap() {
return [
{ url: 'https://yourproduct.com/', lastModified: new Date() },
{ url: 'https://yourproduct.com/pricing', lastModified: new Date() },
];
}
A fixed page has rel=canonical set to its HTTPS self, shows HTTPS in JSON-LD and meta tags, and appears once in the sitemap with the HTTPS URL.
Fix internal links and mixed content
Keep users and crawlers on HTTPS. Update internal links and remove mixed content so nothing loads over HTTP.
Update internal links
Change nav, footers, templates and markdown. Replace absolute HTTP URLs with HTTPS. Relative links are fine if they resolve to HTTPS on the canonical host.
Update external assets
Load images, fonts, scripts and APIs over HTTPS. Replace any hardcoded http:// in CSS, JS and HTML. Use protocol-relative URLs only if you accept current page protocol.
Check for mixed content
Run a crawl on the HTTPS site and report HTTP requests in the waterfall. Browsers will block many active mixed requests.
Rebuild image and font handling
If you use Next.js, use next/image and next/font to self host. This avoids third party HTTP assets and improves Core Web Vitals.
Consider HSTS and the preload list
HTTP Strict Transport Security tells browsers to use HTTPS for your host after first contact. Preload enforces this from the first visit. Apply this only when all redirects and subdomains are ready.
- Add the HSTS header on the canonical host: max-age, includeSubDomains if you can support it, and preload if you meet the preload rules
- Test on a subset of traffic before adding includeSubDomains or preload
- Once preloaded, removal takes time, so be sure before you submit
Use a long max-age, for example a year. That is typical, not measured here.
# HSTS header example
Strict-Transport-Security: max-age=<long-duration>; includeSubDomains; preload
Set up Search Console for HTTPS and submit sitemaps
Verify the HTTPS property. Add a Domain property so it covers both hosts. Submit your new HTTPS sitemap and keep the old HTTP sitemap listed for a while so Google recrawls the old URLs and finds the 301s.
- Verify https://yourproduct.com and the Domain property for your root domain
- Submit /sitemap.xml with HTTPS URLs in the Sitemaps report
- Use the URL Inspection tool on a few key pages to confirm the canonical is HTTPS
- If you also change domains, use the Change of address tool once 301s are live and both properties are verified. This is not required for HTTPS only.
Launch checklist for the switchover day
Pick a low traffic window. Deploy in one release. Keep the old property and logs open while you switch.
Deploy redirects
Enable the 301 rules at the edge. Confirm that HTTP on both www and non-www map in one hop to the chosen HTTPS host and slash form.
Deploy tag and file updates
Publish sitemap with HTTPS URLs, canonicals, hreflang, JSON-LD, and robots.txt links to HTTPS sitemaps if you reference them.
Smoke test key paths
Home, /pricing, /signup, /blog, and your top landing pages. Check cookies, sign in and payments over HTTPS.
Run the redirect test suite
Hit the full redirect map. Fail if any target ends 200 through more than one hop or ends 3xx, 4xx or 5xx.
Submit sitemap and spot check in Search Console
Resubmit the HTTPS sitemap. Inspect a few URLs. Check that Google sees the HTTPS canonical.
Monitor and fix after the move
Expect fluctuation for some weeks. Watch redirects, indexation and user behaviour. Fix what you see in logs and reports fast.
- Run a redirect checker across the map daily for the first week, then weekly for a month
- Check the Search Console Performance report for the HTTPS property. Compare clicks and impressions to the old property
- Use the Indexing reports to find Page with redirect, Soft 404 and Duplicate without user-selected canonical errors and fix the cause
- Keep the HTTP property verified and its sitemap listed for at least a few months
- Keep the 301s live for as long as possible, at least a year, preferably permanently
A fixed site shows stable one-hop redirects, growing HTTPS impressions, and fewer HTTP pages in the index each week.
www, trailing slash and other common traps
Google treats www and non-www as different hosts, and /page and /page/ as different URLs. Pick one for each and enforce it with 301s on every path. Keep internal links consistent. This avoids duplicate content and redirect chains.
- www vs non-www: choose one, 301 the other, set canonicals to the chosen host, verify a Domain property
- Trailing slash: choose a policy, 301 the other, and set Next.js trailingSlash to match your choice
- Avoid redirect chains: map http://www to https://example in one step, not http://www to http://example to https://example
- Parameters: decide which parameters are canonical and keep that consistent in links and sitemaps
Questions
Yes. Configure 301 redirects so every HTTP URL goes to its HTTPS twin in one hop. Do this at the edge or server. Test that the final status is 200 and there are no chains.
You can keep rankings if you 301 every URL in one hop and update canonicals, sitemaps, hreflang and internal links. Some fluctuation is normal for a few weeks while Google recrawls. Browsers also mark HTTP as not secure, so the move improves trust.
No. The Change of address tool is for domain-level moves. For HTTPS only, verify the HTTPS property, submit your HTTPS sitemap, and ensure your 301s are correct.
Keep them for as long as possible. At least a year is a practical minimum. Google’s guidance is to keep redirects permanently when you can.
HSTS is a good safety net once redirects and subdomains are correct. Preload is stricter and hard to unwind. Add preload only when you are sure every subdomain will always serve HTTPS.
Crawl the HTTPS site and inspect the network requests. Any http:// requests should be replaced or upgraded. Browsers often block active mixed content, which can break features and tracking.
Sources
Check my site, free
Run the free check from a URL and get three findings on your redirects, canonical signals and HTTPS coverage in about thirty seconds, no signup.
- Free check, no card
- Read-only, your own accounts
- Readable by your agent
Read next
- GuideWebsite migration SEO checklist: before, during, after
- GuideBuild a redirect map: one old URL, one new URL, tested
- GuideCanonical tags: what they do and the mistakes that cost rankings
- Guidewww or non-www: pick one, redirect the other
- GuideTrailing slash: two URLs for one page unless you decide
- GuideHow to use Google Search Console in ten minutes a week
- GuideShopify SEO: what the platform fixes, what it leaves to you
- GlossaryHTTPS