Websites and Tech

HTTPS

Also called HTTP Secure, secure website, padlock

The secure version of the protocol browsers use to load websites, encrypting everything sent between the visitor and the site.

Quick facts: HTTPS

Category
Websites and Tech
Also called
HTTP Secure, secure website, padlock
Level
Beginner
Affects
Browser warnings, form submissions, data protection, duplicate URLs, a light ranking signal
Where to see it
Browser address bar and console, SSL checkers, Search Console, site crawlers, hosting control panel
In this article4
  1. How HTTPS works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

HTTPS (Hypertext Transfer Protocol Secure) is the encrypted version of the protocol browsers use to request and receive web pages. It scrambles everything that passes between a visitor’s browser and your website, so pages, form entries and logins cannot be read or altered by anyone in between, and it confirms the visitor has reached the real site for that domain.

How HTTPS works

HTTPS relies on an SSL/TLS certificate installed on your server. When a browser connects, the server presents the certificate, which a trusted certificate authority has issued for your domain. The browser checks it is valid and matches the address, then the two agree encryption keys and everything after that travels encrypted. The whole exchange takes a fraction of a second.

Certificates expire and must be renewed. Many hosts now issue free certificates from Let’s Encrypt and renew them automatically. Certificate lifetimes are being shortened in stages across the industry, so automatic renewal matters more each year; a certificate that relies on someone remembering to renew it by hand will eventually lapse and put a full-page warning in front of your visitors.

Why it matters

Browsers treat plain HTTP as a risk. Chrome labels HTTP pages “Not secure”, turns that label red when someone starts typing into a form, and warns before a form is sent to an insecure address, which is enough to stop many people filling in an enquiry form. Google has used HTTPS as a lightweight ranking signal since 2014. It will not lift a weak page, but there is no reason to give it up, and most modern browser features, such as location access, are limited to HTTPS anyway.

For a UK business, there is a data protection side too. UK GDPR requires appropriate technical measures to protect personal data, and sending names, phone numbers and messages from a contact form over an unencrypted connection is hard to defend. HTTPS is now the minimum baseline, not an extra.

Visitors notice less than they used to. At the time of writing (October 2026), Chrome no longer shows a padlock in the address bar for secure sites, using a neutral settings icon instead, because HTTPS is expected. A padlock was never proof that a site is honest, only that the connection is encrypted.

Common mistakes

  • Both versions live. The site loads on HTTP and HTTPS without redirecting, so Google sees duplicate pages. Every HTTP URL should send a 301 redirect to its HTTPS equivalent.
  • Mixed content. An HTTPS page that loads images, scripts or fonts over HTTP. Browsers may block those files or show warnings.
  • Internal links and canonicals still on HTTP. Redirects catch them, but every link, canonical tag and sitemap entry should use HTTPS directly.
  • Certificates that do not cover every version, such as the www and non-www addresses or a subdomain.
  • Forgetting Search Console. Verify the HTTPS version, or better a domain property that covers all versions, so you see the data that matters.

How to act on it

Type your domain with http:// in front and check you land on the https:// version in a single redirect. Open a few key pages and look in the browser console for mixed-content warnings. Check the certificate’s expiry date and confirm with your host that renewal is automatic.

If you are still moving a site to HTTPS, treat it as a small migration: redirect every URL one to one, update internal links, canonical tags and the XML sitemap, and check Search Console for errors in the weeks after. Checking redirects, canonicals and mixed content across a whole site is routine work in a technical SEO audit. Confirm too that every form, including any embedded from a third-party booking or CRM tool, submits to an HTTPS address, which is the practical test of whether enquiries are protected under UK GDPR.

Do and do not

Do

  • 301 redirect every HTTP URL to its HTTPS version
  • Automate certificate renewal
  • Update internal links, canonicals and sitemaps to HTTPS

Do not

  • Leave both HTTP and HTTPS versions live
  • Load images or scripts over HTTP on secure pages
  • Rely on manual certificate renewal

Questions people ask about this

Is HTTPS a Google ranking factor?

Yes, but a light one. Google confirmed it as a signal in 2014 and it works more as a tiebreaker than a boost. The bigger effects are indirect: browser warnings on HTTP pages put people off, and a badly handled switch to HTTPS can cause duplicate pages and lost signals.

Do I need HTTPS if my site does not take payments?

Yes. Any page with a contact form collects personal data, and browsers warn visitors about forms on HTTP pages. HTTPS also stops anyone on the same network from altering your pages in transit. Most hosts provide free certificates, so cost is rarely a reason to go without.

Will moving to HTTPS affect my rankings?

Handled properly, there may be a short period of fluctuation while Google recrawls and processes the redirects, then things settle. Problems come from missing or chained redirects, mixed content and internal links left on HTTP. Map every URL, redirect one to one and monitor Search Console afterwards.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.