HTTPS (Hypertext Transfer Protocol Secure) is the encrypted version of the protocol browsers use to request and receive web pages. It scrambles everything that passes between a visitor’s browser and your website, so pages, form entries and logins cannot be read or altered by anyone in between, and it confirms the visitor has reached the real site for that domain.
How HTTPS works
HTTPS relies on an SSL/TLS certificate installed on your server. When a browser connects, the server presents the certificate, which a trusted certificate authority has issued for your domain. The browser checks it is valid and matches the address, then the two agree encryption keys and everything after that travels encrypted. The whole exchange takes a fraction of a second.
Certificates expire and must be renewed. Many hosts now issue free certificates from Let’s Encrypt and renew them automatically. Certificate lifetimes are being shortened in stages across the industry, so automatic renewal matters more each year; a certificate that relies on someone remembering to renew it by hand will eventually lapse and put a full-page warning in front of your visitors.
Why it matters
Browsers treat plain HTTP as a risk. Chrome labels HTTP pages “Not secure”, turns that label red when someone starts typing into a form, and warns before a form is sent to an insecure address, which is enough to stop many people filling in an enquiry form. Google has used HTTPS as a lightweight ranking signal since 2014. It will not lift a weak page, but there is no reason to give it up, and most modern browser features, such as location access, are limited to HTTPS anyway.
For a UK business, there is a data protection side too. UK GDPR requires appropriate technical measures to protect personal data, and sending names, phone numbers and messages from a contact form over an unencrypted connection is hard to defend. HTTPS is now the minimum baseline, not an extra.
Visitors notice less than they used to. At the time of writing (October 2026), Chrome no longer shows a padlock in the address bar for secure sites, using a neutral settings icon instead, because HTTPS is expected. A padlock was never proof that a site is honest, only that the connection is encrypted.
Common mistakes
- Both versions live. The site loads on HTTP and HTTPS without redirecting, so Google sees duplicate pages. Every HTTP URL should send a 301 redirect to its HTTPS equivalent.
- Mixed content. An HTTPS page that loads images, scripts or fonts over HTTP. Browsers may block those files or show warnings.
- Internal links and canonicals still on HTTP. Redirects catch them, but every link, canonical tag and sitemap entry should use HTTPS directly.
- Certificates that do not cover every version, such as the www and non-www addresses or a subdomain.
- Forgetting Search Console. Verify the HTTPS version, or better a domain property that covers all versions, so you see the data that matters.
How to act on it
Type your domain with http:// in front and check you land on the https:// version in a single redirect. Open a few key pages and look in the browser console for mixed-content warnings. Check the certificate’s expiry date and confirm with your host that renewal is automatic.
If you are still moving a site to HTTPS, treat it as a small migration: redirect every URL one to one, update internal links, canonical tags and the XML sitemap, and check Search Console for errors in the weeks after. Checking redirects, canonicals and mixed content across a whole site is routine work in a technical SEO audit. Confirm too that every form, including any embedded from a third-party booking or CRM tool, submits to an HTTPS address, which is the practical test of whether enquiries are protected under UK GDPR.
