# Moving from HTTP to HTTPS: the checklist that keeps rankings

You are switching your site to HTTPS and want to keep your rankings. This checklist gives you the exact steps: redirects in one hop, updates across tags and files, and the checks to run before and after. It is written for founders who ship their own sites.

Updated 2026-09-14 · Source: https://porteur.ai/guides/http-to-https-migration

## Plan the move and build the redirect map

Treat HTTP to HTTPS as a site move. Rankings hold when every old URL maps to its HTTPS twin in one hop. Plan before you touch production.

1. **Crawl the current HTTP site** Export every live URL. Use your crawler, your XML sitemap, and Search Console indexed pages. Combine and de-duplicate into one list.
2. **Create a two-column redirect map** Old URL in column A, new HTTPS URL in column B. For most rows this is a straight protocol swap. Example: http://yourproduct.com/pricing to https://yourproduct.com/pricing.
3. **Decide your host and slashes** Pick www or non-www. Pick trailing slash or not. Google treats each as different. Make the map reflect your choice across every path.
4. **Spot edge cases** Handle 404s, 410s, parameter patterns, uppercase or mixed-case URLs, and legacy subdomains. Put a precise target or a gone status for each.

> Never point every old URL to the home page. That is a soft 404 pattern.

## Get and install the certificate

Use a valid TLS certificate, covering your chosen host and any extra hostnames you serve. Force TLS 1.2 or newer. Test expiry alerts.

- Choose the exact host you will serve: https://yourproduct.com or https://www.yourproduct.com
- Cover all needed SANs, for example api.yourproduct.com if you serve it under the same cert
- Install the full chain on your CDN or web server
- Set auto renew and monitoring for expiry

If you use a CDN or managed platform, follow their HTTPS guide. Do not enable any redirect toggle until your 301 rules are ready and tested.

## Configure one-hop 301 redirects at the edge

Apply the map at the edge or web server. 301 every HTTP URL to the exact HTTPS twin in one hop. Redirect the alternate host and slash variant too.

- HTTP to HTTPS on the canonical host, one hop
- Non-canonical host to canonical host with HTTPS, one hop
- Slash variant to chosen slash form with HTTPS, one hop

```bash
# nginx map example
map $request_uri $target_suffix {
    default $request_uri;
}
server {
    listen 80;
    server_name yourproduct.com www.yourproduct.com;
    return 301 https://yourproduct.com$target_suffix;
}

```

```javascript
// next.config.js redirects example
module.exports = {
  trailingSlash: false,
  async redirects() {
    return [
      // http -> https handled at proxy/CDN
      { source: '/pricing/', destination: '/pricing', permanent: true },
      // legacy path example
      { source: '/old-guide', destination: '/guides/getting-started', permanent: true },
    ]
  },
}

```

Test the rules in staging with the full map. Use a script to request every old URL, follow redirects, and log the final status and hop count. The final must be 200. The hop count must be one.

## Update canonicals, sitemaps, hreflang and structured data

Google reads your tags and files as hints. Update them to HTTPS on launch, or you send mixed signals and slow the move.

- Canonical tags: point to the HTTPS canonical on each page
- Hreflang: every alternate URL uses HTTPS and matches canonical language targets
- XML sitemaps: list only HTTPS URLs, keep the old HTTP sitemap live for a while so Google recrawls and sees the 301s
- Structured data: fix any URL fields to HTTPS in JSON-LD, including Organization, Breadcrumb, Article or Product markup
- Open Graph and Twitter tags: set og:url and similar to HTTPS

```javascript
// Next.js App Router example
export async function generateMetadata() {
  const base = new URL('https://yourproduct.com');
  return {
    metadataBase: base,
    alternates: { canonical: '/pricing' },
    openGraph: { url: '/pricing', title: 'Pricing' },
  };
}

// app/sitemap.ts lists HTTPS URLs only
export default function sitemap() {
  return [
    { url: 'https://yourproduct.com/', lastModified: new Date() },
    { url: 'https://yourproduct.com/pricing', lastModified: new Date() },
  ];
}

```

A fixed page has rel=canonical set to its HTTPS self, shows HTTPS in JSON-LD and meta tags, and appears once in the sitemap with the HTTPS URL.

## Fix internal links and mixed content

Keep users and crawlers on HTTPS. Update internal links and remove mixed content so nothing loads over HTTP.

1. **Update internal links** Change nav, footers, templates and markdown. Replace absolute HTTP URLs with HTTPS. Relative links are fine if they resolve to HTTPS on the canonical host.
2. **Update external assets** Load images, fonts, scripts and APIs over HTTPS. Replace any hardcoded http:// in CSS, JS and HTML. Use protocol-relative URLs only if you accept current page protocol.
3. **Check for mixed content** Run a crawl on the HTTPS site and report HTTP requests in the waterfall. Browsers will block many active mixed requests.
4. **Rebuild image and font handling** If you use Next.js, use next/image and next/font to self host. This avoids third party HTTP assets and improves Core Web Vitals.

> Mixed content breaks features and can hide page assets from indexing.

## Consider HSTS and the preload list

HTTP Strict Transport Security tells browsers to use HTTPS for your host after first contact. Preload enforces this from the first visit. Apply this only when all redirects and subdomains are ready.

- Add the HSTS header on the canonical host: max-age, includeSubDomains if you can support it, and preload if you meet the preload rules
- Test on a subset of traffic before adding includeSubDomains or preload
- Once preloaded, removal takes time, so be sure before you submit

Use a long max-age, for example a year. That is typical, not measured here.

```bash
# HSTS header example
Strict-Transport-Security: max-age=<long-duration>; includeSubDomains; preload

```

## Set up Search Console for HTTPS and submit sitemaps

Verify the HTTPS property. Add a Domain property so it covers both hosts. Submit your new HTTPS sitemap and keep the old HTTP sitemap listed for a while so Google recrawls the old URLs and finds the 301s.

- Verify https://yourproduct.com and the Domain property for your root domain
- Submit /sitemap.xml with HTTPS URLs in the Sitemaps report
- Use the URL Inspection tool on a few key pages to confirm the canonical is HTTPS
- If you also change domains, use the Change of address tool once 301s are live and both properties are verified. This is not required for HTTPS only.

## Launch checklist for the switchover day

Pick a low traffic window. Deploy in one release. Keep the old property and logs open while you switch.

1. **Deploy redirects** Enable the 301 rules at the edge. Confirm that HTTP on both www and non-www map in one hop to the chosen HTTPS host and slash form.
2. **Deploy tag and file updates** Publish sitemap with HTTPS URLs, canonicals, hreflang, JSON-LD, and robots.txt links to HTTPS sitemaps if you reference them.
3. **Smoke test key paths** Home, /pricing, /signup, /blog, and your top landing pages. Check cookies, sign in and payments over HTTPS.
4. **Run the redirect test suite** Hit the full redirect map. Fail if any target ends 200 through more than one hop or ends 3xx, 4xx or 5xx.
5. **Submit sitemap and spot check in Search Console** Resubmit the HTTPS sitemap. Inspect a few URLs. Check that Google sees the HTTPS canonical.

> Move one thing at a time. Do not combine a domain move, a redesign and URL changes in the same release.

## Monitor and fix after the move

Expect fluctuation for some weeks. Watch redirects, indexation and user behaviour. Fix what you see in logs and reports fast.

- Run a redirect checker across the map daily for the first week, then weekly for a month
- Check the Search Console Performance report for the HTTPS property. Compare clicks and impressions to the old property
- Use the Indexing reports to find Page with redirect, Soft 404 and Duplicate without user-selected canonical errors and fix the cause
- Keep the HTTP property verified and its sitemap listed for at least a few months
- Keep the 301s live for as long as possible, at least a year, preferably permanently

A fixed site shows stable one-hop redirects, growing HTTPS impressions, and fewer HTTP pages in the index each week.

## www, trailing slash and other common traps

Google treats www and non-www as different hosts, and /page and /page/ as different URLs. Pick one for each and enforce it with 301s on every path. Keep internal links consistent. This avoids duplicate content and redirect chains.

- www vs non-www: choose one, 301 the other, set canonicals to the chosen host, verify a Domain property
- Trailing slash: choose a policy, 301 the other, and set Next.js trailingSlash to match your choice
- Avoid redirect chains: map http://www to https://example in one step, not http://www to http://example to https://example
- Parameters: decide which parameters are canonical and keep that consistent in links and sitemaps

## Questions

### Can you redirect HTTP to HTTPS?

Yes. Configure 301 redirects so every HTTP URL goes to its HTTPS twin in one hop. Do this at the edge or server. Test that the final status is 200 and there are no chains.

### Will moving to HTTPS hurt rankings?

You can keep rankings if you 301 every URL in one hop and update canonicals, sitemaps, hreflang and internal links. Some fluctuation is normal for a few weeks while Google recrawls. Browsers also mark HTTP as not secure, so the move improves trust.

### Do I need the Change of address tool for HTTPS migrations?

No. The Change of address tool is for domain-level moves. For HTTPS only, verify the HTTPS property, submit your HTTPS sitemap, and ensure your 301s are correct.

### How long should I keep HTTP to HTTPS redirects?

Keep them for as long as possible. At least a year is a practical minimum. Google’s guidance is to keep redirects permanently when you can.

### Do I need HSTS and preload?

HSTS is a good safety net once redirects and subdomains are correct. Preload is stricter and hard to unwind. Add preload only when you are sure every subdomain will always serve HTTPS.

### How do I check for mixed content after the switch?

Crawl the HTTPS site and inspect the network requests. Any http:// requests should be replaced or upgraded. Browsers often block active mixed content, which can break features and tracking.

## Read next

- [Website migration SEO checklist: before, during, after](https://porteur.ai/guides/website-migration-seo-checklist): Run a safe website migration: crawl and export, build and test one-to-one redirects, switch cleanly, submit sitemaps, use Search Console, and watch the data.
- [Build a redirect map: one old URL, one new URL, tested](https://porteur.ai/guides/redirect-map): A practical redirect map: where to find old URLs, how to match them, store the table, apply 301s, and test every row for one hop and a 200.
- [Canonical tags: what they do and the mistakes that cost rankings](https://porteur.ai/guides/canonical-tag): What a canonical tag does, when to use one, the mistakes that cost rankings, and how to check and fix canonicals on a small site.
- [www or non-www: pick one, redirect the other](https://porteur.ai/guides/www-vs-non-www): Pick www or non-www, there is no SEO gain either way. 301 redirect every path to the chosen host, set canonicals, and verify a Domain property.
- [Trailing slash: two URLs for one page unless you decide](https://porteur.ai/guides/trailing-slash-seo): Google sees /page and /page/ as different. Pick one form, redirect the other, and keep links and your sitemap consistent. Here is how to do it.
- [How to use Google Search Console in ten minutes a week](https://porteur.ai/guides/how-to-use-google-search-console): A quick weekly routine: set four filters, compare 28 days, check pages then queries, and fix three findings, without getting lost in noise.
- [Shopify SEO: what the platform fixes, what it leaves to you](https://porteur.ai/guides/shopify-seo): What Shopify handles for SEO, what you must change, and a practical checklist for a new store: URLs, canonicals, data, speed, and Merchant Center.

Run the free check from a URL and get three findings on your redirects, canonical signals and HTTPS coverage in about thirty seconds, no signup. Free check: https://porteur.ai/
