HTTPS is HTTP sent over an encrypted Transport Layer Security (TLS) connection, which protects the integrity and confidentiality of data between a browser and a website [17]. Google has used HTTPS as a lightweight ranking signal since 2014 [1], and browsers mark plain-HTTP pages as “not secure” [2]. Related practices: avoiding mixed content, sending security headers and keeping a site free of malware: protect users and the site’s standing in search [4][9][13].
1Overview
HTTPS encrypts traffic between visitor and server and lets the browser verify it is talking to the genuine site [17]. For search, it matters in three ways: it is a ranking signal [1], it forms part of Google’s page experience considerations [10], and browsers warn users away from sites without it [2].
2History
In August 2014 Google announced it would use HTTPS as a ranking signal, initially lightweight and affecting fewer than 1% of queries, to encourage site owners to switch [1]. In February 2018 the Chrome team announced that from Chrome 68, released that July, all HTTP pages would be marked “not secure” [2].
In October 2019 Chrome announced it would progressively block mixed content, auto-upgrading images, audio and video to HTTPS where possible [3].
3Moving to HTTPS
Google treats an HTTP-to-HTTPS migration as a site move with URL changes: map each http URL to its https equivalent, redirect permanently, and update internal links, canonicals and sitemaps [12].
Where both versions of a page exist and are equivalent, Google prefers the HTTPS URL as canonical [11]. Free, automated certificate authorities such as Let’s Encrypt have removed cost as a barrier [16].
4Mixed content
Mixed content occurs when a page loaded over HTTPS includes resources fetched over HTTP. Because those resources can be read or altered in transit, they weaken the whole page [4].
5HTTP Strict Transport Security
HSTS is a response header that tells browsers to use only HTTPS for a host for a set time, given by max-age in seconds [5]. It removes the insecure first request that a plain redirect leaves open.
Sites can ask to be included in browsers’ built-in preload list. Requirements include a valid certificate, redirecting HTTP to HTTPS, and an HSTS header with max-age of at least one year, includeSubDomains and preload[6].
6Security headers
| Header | Protects against |
|---|---|
| Content-Security-Policy | Cross-site scripting and unwanted resource loading [7] |
| X-Content-Type-Options: nosniff | MIME-type sniffing attacks [8] |
| CSP frame-ancestors / X-Frame-Options | Clickjacking [7][9] |
| Referrer-Policy | Leaking full URLs to other sites [9] |
| Permissions-Policy | Unneeded access to browser features [9] |
These headers are not ranking signals in themselves. Their value for search is indirect: they reduce the chance of a compromise that leads to warnings or removal [13][15].
7Compromised sites
Google’s Safe Browsing identifies sites hosting malware or social engineering and shows warnings in Chrome and in search results [14]. Site owners are notified through the Security issues report in Search Console, which also handles review requests once a site is cleaned [13].
Hacked content, pages or links injected by an attacker, is covered by Google’s spam policies and can lead to pages being demoted or removed [15].
8Common misconceptions
| Belief | What the sources say |
|---|---|
| HTTPS is a major ranking factor | Google called it lightweight [1] |
| Security headers boost rankings | They protect users; their effect is indirect [9][15] |
| A redirect to https is enough | HSTS closes the first insecure request [5] |
| Paid certificates rank better | No such distinction is documented; free CAs are widely used [16] |
See also
- Security guide: diagrams and quick fixes
- HTTP redirects: the http → https migration
- Search indexing: why HTTPS becomes canonical
- Technical SEO: where security fits overall
References
- [1]“HTTPS as a ranking signal”. Google Search Central Blog, August 2014. developers.google.com/search/blog/2014/08/https-as-ranking-signal
- [2]“A secure web is here to stay”. Chromium Blog, February 2018. blog.chromium.org/2018/02/a-secure-web-is-here-to-stay.html
- [3]“No more mixed messages about HTTPS”. Chromium Blog, October 2019. blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html
- [4]“Mixed content”. MDN Web Docs. developer.mozilla.org/en-US/docs/Web/Security/Mixed_content
- [5]“RFC 6797: HTTP Strict Transport Security (HSTS)”. IETF, November 2012. www.rfc-editor.org/rfc/rfc6797
- [6]“HSTS Preload List Submission”. hstspreload.org. hstspreload.org/
- [7]“Content Security Policy (CSP)”. MDN Web Docs. developer.mozilla.org/en-US/docs/Web/HTTP/CSP
- [8]“X-Content-Type-Options”. MDN Web Docs. developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options
- [9]“OWASP Secure Headers Project”. OWASP Foundation. owasp.org/www-project-secure-headers/
- [10]“Understanding page experience in Google Search results”. Google Search Central. developers.google.com/search/docs/appearance/page-experience
- [11]“How to specify a canonical URL with rel="canonical" and other methods”. Google Search Central. developers.google.com/search/docs/crawling-indexing/consolidate-duplicate-urls
- [12]“Site moves with URL changes”. Google Search Central. developers.google.com/search/docs/crawling-indexing/site-move-with-url-changes
- [13]“Security issues report”. Search Console Help. support.google.com/webmasters/answer/9044101
- [14]“Safe Browsing site status”. Google Transparency Report. transparencyreport.google.com/safe-browsing/overview
- [15]“Spam policies for Google web search”. Google Search Central. developers.google.com/search/docs/essentials/spam-policies
- [16]“About Let’s Encrypt”. Let’s Encrypt. letsencrypt.org/about/
- [17]“RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3”. IETF, August 2018. www.rfc-editor.org/rfc/rfc8446