Technical SEO · Guide

What Is HTTPS in SEO?

Largely a settled subject, worth saying so rather than inflating it. A site without a secure connection in this decade has a problem, though the search consideration is the smallest part of it. The useful content here is what persists after a site has moved.

Updated: August 2026
Written by: Andrew Odgers, Managing Director
Reading time: 11 minutes
Said candidly, because inflating it would be easy

This One Is Largely Settled

Secure connections are the default expectation now. Browsers warn visitors when one is missing, hosting includes what is needed and the vast majority of sites have already moved. There is less to discuss here than there was.

What changed. It stopped being optional.

Secure connections went from a feature of banking sites to the assumed condition of every site. That transition is complete rather than in progress.

Who is still affected. A small remainder.

Older sites nobody has touched, sites on neglected hosting and internal systems that were never revisited. Genuinely a minority. Each one has an obvious problem.

Why the search angle is the smallest part. The order of costs.

A site without this loses visitors to a browser warning long before any search consideration matters. Leading with search puts the least significant reason first.

What is worth reading on for. The leftovers.

Sites that moved years ago frequently carry residual problems nobody resolved. Mixed content and lapsing certificates are the two that actually cost businesses money. They are blocks five and seven.

Why we are not inflating it. It would be simple to.

This subject could be written as an urgent priority with a ranking argument attached. That would be a sales document rather than a guide. It would be recognised as one.

In plain terms

Certificates

A certificate is what makes the secure connection possible. Most hosting includes one, most platforms handle it invisibly, so for most businesses this is not a purchasing decision at all.

What it does. Two things.

It allows the connection between a visitor and your site to be encrypted. It also confirms that the site is the one it claims to be. The second is why it comes from an issuing authority rather than from you.

Where you get one. Usually already included.

Hosting and managed platforms provide them as standard now, frequently renewed automatically. A business paying separately for one is either on old hosting or has a specific requirement.

Whether paid ones are better. Not for this.

The encryption is the same. Paid certificates offer extended validation of the organisation and broader coverage options. None of that affects search in any way.

The kinds that exist. Three, briefly.

One covering a single address, one covering several, then one covering a domain with all its subdomains. Which you need is a technical question your host can answer in a sentence.

What they do not do. Vouch for the business.

A certificate confirms the connection is genuinely to that address. It says nothing about whether the business behind it is reputable, which is worth knowing since the padlock is sometimes read as an endorsement.

What we are not publishing. Installation.

Obtaining and installing one is a hosting task with steps that differ by provider. A developer or host has that. Putting it here would help nobody.

The published position, attributed and dated

How It Affects Rankings

It is a confirmed consideration and a very small one. Google said so directly. The wording matters enough to attribute rather than paraphrase loosely.

What Google published. A dated statement.

On 6 August 2014, Google announced on its Search Central blog that it was starting to use secure connections as a ranking signal. It described this as a very lightweight signal, affecting fewer than one per cent of global queries and carrying less weight than other signals such as high-quality content.

What it also said. That this might change.

The same announcement noted the signal might be strengthened over time, to encourage adoption. Whether it has been is not something Google has published a figure for since.

What that means for you. Treat it as settled, not as a lever.

Being on a secure connection removes a small disadvantage. It does not create an advantage, because effectively every competitor has done it too.

Why we will not claim more. Nothing supports it.

Guidance describing this as a significant ranking factor is asserting something beyond the published position. We hold to what was actually stated.

The correct reason to do it. Everything else.

Visitor trust, browser behaviour and not transmitting form submissions in the open. Block four covers why that reasoning is stronger anyway.

Where the commercial argument actually sits

The Browser Warning Is The Real Cost

A visitor arriving at an insecure site sees a warning from their browser. That costs conversions long before it costs anything in search, which reframes the whole subject.

What the visitor sees. An explicit caution.

Browsers mark sites without a secure connection as not secure, in the address bar, before anybody reads a word of the page. That is a third party telling your prospect to be careful.

What it does to them. Creates doubt at the worst moment.

Somebody arriving ready to enquire now has a reason to hesitate. Most will not investigate whether the warning matters, they will simply feel less confident.

Where it costs most. Forms.

Warnings are most prominent where information is being entered, which is exactly where enquiries and orders happen. The warning appears at the point of commitment.

Why this outweighs the search argument. Different magnitudes.

A very lightweight ranking consideration against a visible warning at the point of purchase. One of those is measurable in a business and the other is not.

What that means for the decision. It is not an SEO decision.

Moving to a secure connection is a business and trust decision that happens to have a minor search benefit. Selling it the other way round is misleading, however common.

The commonest leftover after a move

Mixed Content

A secure page loading some of its parts insecurely. It produces a warning, can stop parts of the page working, then persists as the most common thing left behind by a site that moved years ago.

What causes it. Hardcoded references.

Images, scripts or stylesheets referenced by their old insecure addresses, written into the content or a template before the move. The page itself is secure and its ingredients are not.

What it does. Two levels of damage.

At best a browser reports the page as only partly secure, undermining the trust the move was meant to establish. At worst the browser refuses to load the offending parts, so something on the page stops working.

Which failures are worst. Blocked scripts.

A blocked image is visible and annoying. A blocked script can break a form, a booking widget or a payment step, which is invisible to whoever tested the design.

Why it survives for years. It hides in old content.

Templates get fixed during a move because somebody looks at them. Individual old pages with references written into the content do not. Nobody revisits a post from four years ago.

How it is identified. Browser reporting.

Any browser will report insecure parts on a page it loads, which makes finding examples straightforward. Fixing them across a large site is a development task rather than a browsing one.

Kept short, because another cluster owns it

Migrating To HTTPS

This is a migration rather than a setting change, because every address on the site changes. That single fact is what people underestimate. It is why this belongs with the migration discipline.

Why it is a migration. Every address moves.

An insecure address and its secure equivalent are two different addresses. Moving means the whole site relocates, which is exactly what a migration is.

What that implies. Redirects, everywhere.

Every old address needs sending to its new equivalent, permanently. Status codes covers what permanent means and why the temporary version is a common error.

What else needs updating. Everything containing addresses.

Internal links, the sitemap, canonical nominations and anything else stating an address. Those are the pieces that get missed. Each one leaves the site pointing at its old self.

Why it is usually straightforward. Only one thing changed.

Unlike a redesign, the structure and content are identical. That makes it among the more predictable migrations, provided nothing else is changed at the same time.

Where the discipline sits. The migrations material.

Our site migrations guides own this as a named migration type, including the rule about not changing two things at once. We are not repeating the procedure here.

The maintenance point nobody plans for

Certificates Expire

Certificates have an end date. When one lapses the failure is abrupt and total, which makes it unlike anything else in this section. It needs monitoring and an owner.

What happens when one lapses. The site becomes unusable.

Browsers present a full page warning rather than a small marker. Many visitors will not proceed past it. There is no gradual decline, the site simply stops being visitable for most people.

Why that is different in kind. No warning period.

Every other problem in this cluster degrades slowly and gives somebody a chance to notice. This one goes from working to broken on a known date that nobody wrote down.

Why it still happens. Automatic renewal is not universal.

Most modern arrangements renew without intervention, which is why this feels solved. Renewals fail quietly, older setups need manual action and a domain moved between providers can lose its arrangement.

What it needs. Monitoring and a name.

Something checking the expiry date and alerting before it arrives, plus a person responsible for acting. That is the same governance point the robots pillar makes about its own file.

Who usually finds out first. A customer.

Businesses discover this when somebody telephones to say the website is showing a warning. That is a poor way to learn. A monitoring arrangement costs almost nothing.

What to check now. Two things.

Whether renewal is automatic and whether anybody is alerted if it fails. If the answer to either is unclear, it is worth ten minutes today rather than a morning at some point.

Website migrations

Is your renewal
automatic, plus
who is told?

A lapsed certificate takes a site from working to unvisitable on a known date, with no gradual decline to notice. Most businesses find out when a customer telephones. Monitoring costs almost nothing and needs a named person to act on it.

What we check:

Certificate present Renewal automatic Expiry monitored Alerts to a named person No mixed content Old pages checked too Permanent redirects Addresses updated everywhere

This is a trust decision with a minor search benefit, not the other way round.

The full guide series

Every guide.
One practice.

How search finds and stores a site, what your own files are telling it, addresses and duplication, status codes, mobile, hosting and what a real audit contains.

Questions people ask

Secure Connections, Briefly

Will moving to HTTPS improve our rankings?
Barely. Google said so directly. On 6 August 2014 it announced it was starting to use secure connections as a ranking signal, describing it as a very lightweight signal affecting fewer than one per cent of global queries and carrying less weight than signals such as high-quality content. It removes a small disadvantage rather than creating an advantage, since every competitor has done it too.
So why bother?
Because of what visitors see. Browsers mark sites without a secure connection as not secure in the address bar, before anybody reads a word, with the warning most prominent where information is being entered. That is a third party telling your prospect to hesitate at the exact point they were going to enquire.
Do we need to buy a certificate?
Probably not. Hosting and managed platforms provide them as standard now, frequently renewing automatically, so a business paying separately is either on old hosting or has a specific requirement. The encryption is identical either way: paid certificates offer extended validation and broader coverage, none of which affects search.
Our site says not fully secure. What does that mean?
The page is secure while some of its parts are not, usually images or scripts referenced by their old addresses before a move. At best the browser reports the page as only partly secure. At worst it refuses to load the offending parts, which can break a form or a booking step invisibly. It survives for years because it hides in old content rather than templates.
Is moving to HTTPS just a setting?
No, it is a migration, because an insecure address and its secure equivalent are two different addresses. Every old address needs permanently redirecting. Internal links, the sitemap and canonical nominations all need updating too. It is among the more predictable migrations, provided nothing else is changed at the same time.
What happens if our certificate expires?
The site effectively stops being visitable. Browsers present a full page warning rather than a small marker and many visitors will not proceed past it. Unlike everything else here, there is no gradual decline: it goes from working to broken on a known date nobody wrote down. Most businesses find out when a customer telephones.