Home/SEO Guide/Reference/HTTPS and security
Reference article · 17 sources · last reviewed 1 Oct 2026

HTTPS and website security for SEO

PRACTICAL GUIDEPrefer diagrams and quick fixes? The HTTPS and security guide covers this visually.Open the guide →

HTTPS is HTTP sent over an encrypted Transport Layer Security (TLS) connection, which protects the integrity and confidentiality of data between a browser and a website [17]. Google has used HTTPS as a lightweight ranking signal since 2014 [1], and browsers mark plain-HTTP pages as “not secure” [2]. Related practices: avoiding mixed content, sending security headers and keeping a site free of malware: protect users and the site’s standing in search [4][9][13].

IN SHORT
  • HTTPS has been a lightweight Google ranking signal since August 2014 [1].
  • Chrome has labelled all HTTP pages “not secure” since July 2018 [2].
  • Browsers block mixed scripts and upgrade or block mixed images [3][4].
  • When HTTP and HTTPS versions are equivalent, Google prefers HTTPS as canonical [11].

1Overview

HTTPS encrypts traffic between visitor and server and lets the browser verify it is talking to the genuine site [17]. For search, it matters in three ways: it is a ranking signal [1], it forms part of Google’s page experience considerations [10], and browsers warn users away from sites without it [2].

2History

In August 2014 Google announced it would use HTTPS as a ranking signal, initially lightweight and affecting fewer than 1% of queries, to encourage site owners to switch [1]. In February 2018 the Chrome team announced that from Chrome 68, released that July, all HTTP pages would be marked “not secure” [2].

In October 2019 Chrome announced it would progressively block mixed content, auto-upgrading images, audio and video to HTTPS where possible [3].

YearEvent
2012HSTS standardised as RFC 6797 [5]
2014HTTPS becomes a Google ranking signal [1]
2018Chrome 68 marks HTTP pages “not secure” [2]; TLS 1.3 published [17]
2019–20Chrome begins blocking and auto-upgrading mixed content [3]

3Moving to HTTPS

Google treats an HTTP-to-HTTPS migration as a site move with URL changes: map each http URL to its https equivalent, redirect permanently, and update internal links, canonicals and sitemaps [12].

Where both versions of a page exist and are equivalent, Google prefers the HTTPS URL as canonical [11]. Free, automated certificate authorities such as Let’s Encrypt have removed cost as a barrier [16].

4Mixed content

Mixed content occurs when a page loaded over HTTPS includes resources fetched over HTTP. Because those resources can be read or altered in transit, they weaken the whole page [4].

TypeExamplesBrowser behaviour
Active (blockable)Scripts, stylesheets, iframes, fetch requestsBlocked [4]
Passive (upgradable)Images, audio, videoUpgraded to HTTPS, or blocked if that fails [3][4]

5HTTP Strict Transport Security

HSTS is a response header that tells browsers to use only HTTPS for a host for a set time, given by max-age in seconds [5]. It removes the insecure first request that a plain redirect leaves open.

Sites can ask to be included in browsers’ built-in preload list. Requirements include a valid certificate, redirecting HTTP to HTTPS, and an HSTS header with max-age of at least one year, includeSubDomains and preload[6].

KEY FACTRemoving a domain from the HSTS preload list can take months to reach users’ browsers, so preload is effectively a long-term commitment [6].

6Security headers

The OWASP Secure Headers Project maintains recommended values [9].
HeaderProtects against
Content-Security-PolicyCross-site scripting and unwanted resource loading [7]
X-Content-Type-Options: nosniffMIME-type sniffing attacks [8]
CSP frame-ancestors / X-Frame-OptionsClickjacking [7][9]
Referrer-PolicyLeaking full URLs to other sites [9]
Permissions-PolicyUnneeded access to browser features [9]

These headers are not ranking signals in themselves. Their value for search is indirect: they reduce the chance of a compromise that leads to warnings or removal [13][15].

7Compromised sites

Google’s Safe Browsing identifies sites hosting malware or social engineering and shows warnings in Chrome and in search results [14]. Site owners are notified through the Security issues report in Search Console, which also handles review requests once a site is cleaned [13].

Hacked content, pages or links injected by an attacker, is covered by Google’s spam policies and can lead to pages being demoted or removed [15].

8Common misconceptions

BeliefWhat the sources say
HTTPS is a major ranking factorGoogle called it lightweight [1]
Security headers boost rankingsThey protect users; their effect is indirect [9][15]
A redirect to https is enoughHSTS closes the first insecure request [5]
Paid certificates rank betterNo such distinction is documented; free CAs are widely used [16]

See also

References

  1. [1]“HTTPS as a ranking signal”. Google Search Central Blog, August 2014. developers.google.com/search/blog/2014/08/https-as-ranking-signal
  2. [2]“A secure web is here to stay”. Chromium Blog, February 2018. blog.chromium.org/2018/02/a-secure-web-is-here-to-stay.html
  3. [3]“No more mixed messages about HTTPS”. Chromium Blog, October 2019. blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html
  4. [4]“Mixed content”. MDN Web Docs. developer.mozilla.org/en-US/docs/Web/Security/Mixed_content
  5. [5]“RFC 6797: HTTP Strict Transport Security (HSTS)”. IETF, November 2012. www.rfc-editor.org/rfc/rfc6797
  6. [6]“HSTS Preload List Submission”. hstspreload.org. hstspreload.org/
  7. [7]“Content Security Policy (CSP)”. MDN Web Docs. developer.mozilla.org/en-US/docs/Web/HTTP/CSP
  8. [8]“X-Content-Type-Options”. MDN Web Docs. developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options
  9. [9]“OWASP Secure Headers Project”. OWASP Foundation. owasp.org/www-project-secure-headers/
  10. [10]“Understanding page experience in Google Search results”. Google Search Central. developers.google.com/search/docs/appearance/page-experience
  11. [11]“How to specify a canonical URL with rel="canonical" and other methods”. Google Search Central. developers.google.com/search/docs/crawling-indexing/consolidate-duplicate-urls
  12. [12]“Site moves with URL changes”. Google Search Central. developers.google.com/search/docs/crawling-indexing/site-move-with-url-changes
  13. [13]“Security issues report”. Search Console Help. support.google.com/webmasters/answer/9044101
  14. [14]“Safe Browsing site status”. Google Transparency Report. transparencyreport.google.com/safe-browsing/overview
  15. [15]“Spam policies for Google web search”. Google Search Central. developers.google.com/search/docs/essentials/spam-policies
  16. [16]“About Let’s Encrypt”. Let’s Encrypt. letsencrypt.org/about/
  17. [17]“RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3”. IETF, August 2018. www.rfc-editor.org/rfc/rfc8446
CITE THIS ARTICLEKalenux. (2026). HTTPS and website security for SEO. In Kalenux SEO Guide. Last reviewed 1 Oct 2026. https://kalenux.com.tr/reference/https-and-security