What is HTTPS?

HTTPS (Hypertext Transfer Protocol Secure) is HTTP carried over an encrypted TLS connection. It protects what passes between a visitor's browser and your server, including logins, form data, and the pages themselves, from being read or altered in transit. The padlock and https:// in the address bar show it is active.

Google announced HTTPS as a lightweight ranking signal in 2014, and since 2018 Chrome labels HTTP pages "Not secure". In practice HTTPS is now the default expectation: free certificates from Let's Encrypt and most hosts removed the cost barrier, and features such as HTTP/2, HTTP/3, geolocation, and service workers require a secure context.

How it works

The server holds a TLS certificate issued by a certificate authority for your domain. When a browser connects, the two perform a handshake: the browser verifies the certificate, they agree on encryption keys, and all further traffic is encrypted.

For SEO, the important parts come after the certificate is installed:

  • Redirect all HTTP URLs to HTTPS with 301 redirects, one hop each.
  • Update canonicals, sitemaps, and internal links to HTTPS so every signal agrees.
  • Fix mixed content: images, scripts, or styles still loaded over http://. Browsers block or warn about them.
  • Consider HSTS, a response header telling browsers to always use HTTPS for your domain.

Google treats HTTP and HTTPS as separate URLs, so a site reachable at both without redirects has duplicate content.

Example

Check the redirect with curl:

code
$ curl -I http://example.com/pour-over-guide/
HTTP/1.1 301 Moved Permanently
Location: https://example.com/pour-over-guide/

An HSTS header on the HTTPS response:

code
Strict-Transport-Security: max-age=31536000; includeSubDomains

In WordPress

Install the certificate through your host, then change both WordPress Address and Site Address in Settings → General to https://. Old post content may still contain http:// image URLs; a search-and-replace tool or WP-CLI's search-replace command fixes them. WordPress Site Health warns when the site is not using HTTPS. Hydrogen SEO's site health score checks HTTPS in its security area, and canonicals follow your site URL; see site health score.

Common mistakes

  • Installing a certificate but not redirecting HTTP, leaving two copies of the site.
  • Redirect chains like http://example.com to http://www.example.com to https://www.example.com.
  • Mixed content from hardcoded http:// asset URLs.
  • Letting certificates expire, which shows visitors a full-page warning.

Common questions

Is HTTPS a ranking factor?

Yes, but a lightweight one. Its larger effects are trust, browser warnings on HTTP pages, and access to modern web features.

Will moving to HTTPS hurt my rankings?

A clean migration with one-hop 301 redirects and updated canonicals and sitemaps usually causes little or no lasting change. Problems come from missing redirects and mixed signals.