In 2026, a website without HTTPS is not just behind the times; it is actively putting visitors off. Browsers flag it as "Not secure", forms on it can be intercepted, and from Chrome 154 onwards users with default settings are asked for permission before Chrome loads a public HTTP site at all.
Yet HTTPS is often misunderstood in SEO. Some treat it as a magic ranking boost; others assume that once the padlock appears, the job is done. Neither is true. HTTPS is a modest ranking signal with large indirect benefits, and a badly executed switch can cause more harm than staying on HTTP ever did.
This guide covers how Google treats HTTPS, why the latest browser changes matter, how to migrate safely step by step and the technical mistakes that quietly cost sites traffic.
Key Takeaways
- HTTPS encrypts data between browser and server using a TLS certificate; free certificates are widely available.
- Google confirmed HTTPS as a lightweight ranking signal in 2014 and prefers HTTPS URLs as canonical.
- Google announced that Chrome 154, due in October 2026, turns on "Always Use Secure Connections" by default, so public HTTP sites trigger a warning before loading.
- Moving from HTTP to HTTPS is a site move: use page-to-page 301 redirects and update every internal reference.
- Fix mixed content, redirect chains and stray HTTP canonicals, then add HSTS once stable.
What Is HTTPS?
HTTPS (Hypertext Transfer Protocol Secure) is HTTP sent over an encrypted TLS connection. When a browser connects, the server presents a certificate issued by a certificate authority; the browser checks it, the two agree on encryption keys and all further data is encrypted. That protects three things:
- Confidentiality: passwords, form submissions and payment details cannot be read in transit.
- Integrity: networks cannot inject ads or malware into your pages along the way.
- Authentication: visitors can be confident they are talking to your domain, not an impostor.
Certificates no longer need to be expensive. Let's Encrypt, run by the nonprofit Internet Security Research Group, provides free, automated certificates, and most hosts now include them as standard.
How HTTPS Affects SEO
1. A lightweight ranking signal
In August 2014 Google announced HTTPS as a ranking signal. As 9to5Google reported from the announcement, Google described it as only a very lightweight signal affecting fewer than 1% of global queries at the time, carrying less weight than content quality. Do not expect a ranking jump from HTTPS alone.
2. Part of page experience
Google's page experience guidance includes a self-assessment question: "Are your pages served in a secure fashion?" Google is clear there is no single page experience ranking signal, and that beyond Core Web Vitals these aspects do not directly boost rankings, but a secure, smooth experience supports success when many results are equally helpful.
3. Canonicalization
When the same content is available on both protocols, Google's canonicalization documentation states that it prefers HTTPS pages over equivalent HTTP pages as canonical. That helps, but only if your redirects, canonical tags, sitemaps and internal links all agree. Mixed signals make Google's choice harder.
4. Trust, conversions and browser behaviour
The biggest commercial impact of HTTPS is on users. Chrome and other browsers label HTTP pages as not secure, which discourages enquiries and purchases. And the bar keeps rising:
“One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”.”
— Google Chrome Security Blog, HTTPS by default (October 2025)
With that setting on, Chrome asks for the user's permission before the first visit to a public site without HTTPS. The same post notes that HTTPS adoption, measured in Google's transparency data, had already reached roughly the 95–99% range around 2020 before plateauing, so an HTTP-only business site now stands out for the wrong reasons.
5. Performance features
Modern protocols such as HTTP/2 and HTTP/3 are only supported by browsers over encrypted connections, as are many newer browser features. A well-configured HTTPS site can be faster than its HTTP equivalent, which helps the page speed work you are already doing.
HTTP vs HTTPS at a Glance
| Factor | HTTP | HTTPS |
|---|---|---|
| Encryption | None; data sent in plain text | Encrypted with TLS |
| Browser label | "Not secure"; Chrome may warn before loading | Standard secure connection |
| Google ranking signal | No benefit | Lightweight positive signal |
| Canonical preference | Not preferred | Preferred when duplicates exist |
| HTTP/2 and HTTP/3 in browsers | Not available | Available |
| Default port | 80 | 443 |
How to Migrate From HTTP to HTTPS: Step by Step
Google treats a protocol change as a site move with URL changes. Its site move documentation is the best checklist; here is how we apply it:
- Install and test the certificate. Cover every hostname you use, including www and non-www, and any subdomains that serve pages.
- Crawl the current site to record every HTTP URL, plus top pages by traffic and backlinks.
- Update internal references. Internal links, canonical tags, hreflang, structured data, image and script URLs, and XML sitemaps should all use HTTPS.
- Fix mixed content. Every resource must load over HTTPS; check third-party embeds and hard-coded URLs in templates and the database. On WordPress, also update the site address settings; our WordPress SEO guide covers the key settings.
- Add server-side 301 redirects from every HTTP URL to its exact HTTPS equivalent, not to the homepage. See our guide to 301 vs 302 redirects.
- Avoid redirect chains. Combine protocol and hostname rules so that an HTTP non-www URL reaches HTTPS www in a single hop; our guide to redirect chains shows how to test this.
- Verify the HTTPS property in Search Console (a Domain property covers both protocols) and submit the HTTPS sitemap. Google says the Change of Address tool is not needed for HTTP to HTTPS moves.
- Update external references you control: Google Business Profile, social profiles, ad destination URLs and key directory listings.
- Monitor indexing, traffic and crawl stats for several weeks, and keep the redirects in place long term.
- Enable HSTS once everything works, starting with a short
max-age.
A typical HSTS header, as documented by MDN, looks like this:
Strict-Transport-Security: max-age=31536000; includeSubDomains
Only add preload and submit your domain to the browser preload list when you are certain every subdomain supports HTTPS, as it is hard to undo. For bigger restructures, our full website migration checklist covers the wider process.
HTTPS Health Checklist
| Check | Tool | Good result |
|---|---|---|
| Certificate valid and not expiring soon | Browser padlock details, SSL testing tools | Valid chain, auto-renewal enabled |
| HTTP URLs redirect in one hop | Crawler, curl -I | Single 301 to the HTTPS equivalent |
| No mixed content | Browser console, site crawler | Zero HTTP resources on HTTPS pages |
| Canonicals and sitemaps use HTTPS | Crawler, sitemap file | No HTTP URLs listed |
| Internal links use HTTPS | Crawler outlinks report | No links to HTTP versions |
| Google indexing HTTPS URLs | Search Console URL Inspection | Google-selected canonical is HTTPS |
Our Google Search Console guide explains how to use URL Inspection and the Page indexing report for these checks, and our guide to HTTP status codes explains the responses you should expect.
Common Mistakes
- Redirecting everything to the HTTPS homepage instead of page-to-page redirects.
- Using 302 redirects for a permanent protocol change.
- Leaving canonical tags or sitemaps on HTTP, which contradicts the redirects.
- Mixed content from hard-coded image, font or script URLs.
- Letting the certificate expire. Browsers then show a full-page security warning; set up automatic renewal and monitoring.
- Forgetting subdomains such as blog, shop or help centres.
- Enabling HSTS preload too early, before every subdomain is ready.
Related Guides
- Log File Analysis for SEO: A Beginner’s Guide
- Website Migration SEO Checklist: Move Without Losing Traffic
- Orphan Pages: How to Find and Fix Them
Frequently Asked Questions
Is HTTPS a Google ranking factor?
Yes, but a small one. When Google announced it in 2014 it described HTTPS as a very lightweight signal affecting fewer than 1% of global queries. Its bigger impact today is on user trust, browser warnings and canonicalization.
Will switching to HTTPS hurt my rankings?
A well-executed move with page-to-page 301 redirects and updated internal links typically causes little disruption. Problems usually come from missing redirects, mixed content or canonical tags still pointing to HTTP URLs.
Do I need a paid SSL certificate?
Not for SEO. Free domain-validated certificates from Let's Encrypt or your host encrypt traffic just as well. Paid certificates mainly add organisational validation, warranties or support.
Do I need to use Change of Address in Search Console when moving to HTTPS?
No. Google's site move documentation says the Change of Address tool is not needed for HTTP to HTTPS moves. Verify the HTTPS property, submit the new sitemap and monitor.
What is mixed content?
Mixed content happens when an HTTPS page loads resources such as images, scripts or stylesheets over HTTP. Browsers may block or upgrade those resources and can show the page as not fully secure, so every resource should load over HTTPS.
Should I use HSTS?
Yes, once your HTTPS setup is stable. HSTS tells browsers to always use HTTPS for your domain, removing the insecure first request. Start with a short max-age, then increase it once you are confident.
Conclusion
HTTPS will not catapult a page to the top of Google, but in 2026 it is non-negotiable. It protects users, supports trust and conversions, removes browser warnings, enables faster protocols and gives Google a clean, consistent version of your site to index. The key is a careful migration and ongoing maintenance, not just a certificate install.
If your site still has HTTP pages, mixed content or messy redirects, our SEO hosting and web development teams can fix it properly. Get a free quote and we will check your setup.
References
- Google Search Central Blog: HTTPS as a ranking signal (August 2014)
- Google Chrome Security Blog: HTTPS by default
- Google Search Central: How to specify a canonical URL with rel="canonical" and other methods
- Google Search Central: Site moves with URL changes
- Google Search Central: Understanding page experience in Google Search results
- MDN Web Docs: Strict-Transport-Security
- 9to5Google: Google starts giving search preference to HTTPS encrypted websites
- Semrush: What Is HTTPS & How Does It Work?



