HTTPS and Security
HTTPS encrypts the connection between a browser and a website. It is a lightweight Google ranking signal, a requirement for modern browser features and a basic trust signal for users.
  • Every URL should load over HTTPS, with http redirected to https in a single 301 hop.
  • Fix mixed content so no page loads resources over http.
  • Add HSTS once you are confident everything works over HTTPS.
  • Certificate expiry is a real cause of sudden traffic loss, so automate renewal.
  • Hacked content and malware lead to warnings and manual actions that remove traffic overnight.

HTTPS is HTTP with encryption provided by TLS. Google announced it as a ranking signal in 2014. Its weight is small, but browsers now label http pages as "Not secure", and features such as HTTP/2, HTTP/3, service workers and geolocation need a secure connection. In practice HTTPS is simply the default.

Setting it up properly

  • Install a valid certificate that covers every hostname you use, including www and non-www. Free certificates from Let's Encrypt are fine. Extended validation certificates bring no SEO advantage.
  • Redirect http to https with a 301, in one hop, preserving the path.
  • Update internal links, canonicals, hreflang, sitemaps and structured data to https URLs.
  • Automate renewal. An expired certificate throws a full-page browser warning and stops crawlers.
  • Use modern protocols. TLS 1.2 or 1.3. Older versions are deprecated.

Mixed content

Mixed content is an https page that loads images, scripts or styles over http. Browsers block active mixed content such as scripts and may upgrade or block passive content such as images. Find and fix the references at source. As a safety net you can add:

 Content-Security-Policy: upgrade-insecure-requests 

HSTS

HTTP Strict Transport Security tells browsers to use HTTPS for your domain without first trying http, which removes a redirect and closes a security gap.

 Strict-Transport-Security: max-age=31536000; includeSubDomains; preload 

Start with a short max-age and increase it. The includeSubDomains and preload options are hard to reverse, so make sure every subdomain supports HTTPS before using them. One side effect to know about: browsers perform the http to https switch internally and report it as a 307. Crawling tools sometimes show this, and it is not a real server redirect.

Other useful security headers

  • Content-Security-Policy: limits where scripts and other resources can load from, reducing cross-site scripting risk.
  • X-Content-Type-Options: nosniff: stops browsers guessing MIME types.
  • X-Frame-Options or the frame-ancestors CSP directive: prevents clickjacking.
  • Referrer-Policy: controls how much referrer data you pass on. The strict-origin-when-cross-origin default is a sensible balance.
  • Permissions-Policy: restricts browser features such as camera and microphone.

None of these is a ranking factor. They protect users and reduce the chance of the kind of compromise that does damage rankings.

Hacked sites and manual actions

Security incidents affect SEO directly. Injected spam pages, hidden links, cloaked redirects and malware can all trigger Safe Browsing warnings or manual actions. Symptoms include unfamiliar URLs in Search Console, foreign-language titles in results and unexpected spikes in indexed pages. Keep your CMS and plugins patched, use strong authentication, and check the Security issues and Manual actions reports regularly.

Moving from http to https

Treat it as a site migration, since every URL changes. Redirect one to one, verify the https property in Search Console (a domain property covers both), update the sitemap and monitor. Rankings usually settle within a few weeks.

Common mistakes

  • Redirect chains such as http non-www to http www to https www.
  • Certificates that do not cover all subdomains.
  • Canonicals or sitemap URLs still on http.
  • Both http and https versions returning 200.
  • Turning on HSTS preload before checking legacy subdomains.
  • Leaving staging sites publicly accessible and indexable.

How to test

  • Crawl the site and filter for http URLs and mixed content.
  • Use an SSL testing service to check certificate and protocol configuration.
  • Check response headers with curl -I or browser developer tools.
  • Review the HTTPS report in Search Console.

The GEO angle

Security tooling is now the most common reason AI crawlers cannot reach a site. Web application firewalls and bot-management products often block or challenge AI user agents by default. Review those rules so the decision about which AI bots to allow is one you made, not one your vendor made for you.

Add your title here

This is a paragraph. Writing in paragraphs lets visitors find what they are looking for quickly and easily. Make sure the title suits the content of this text.

Contact Us Amy Time