What it looks like
You see it at the start of a web address.
http://www.example.com/ not secure
https://www.example.com/ secure
The extra "s" means the connection is encrypted. To offer HTTPS, a site needs a certificate. That is a small file installed on the server that confirms the site is the one it claims to be. Most hosting companies provide a certificate for free and can switch it on for you.
Why it matters
- Privacy. Encryption stops others on the same network from reading or changing what travels between the visitor and your site. This matters most for logins, forms and payments, but it applies to every page.
- Trust. Browsers mark plain HTTP pages as not secure in the address bar. That warning can put visitors off.
- Search. Google has said HTTPS is a lightweight ranking signal. It will not lift a weak page, but there is no reason to give it up.
Moving a site to HTTPS changes every address on it. Each old HTTP address needs a permanent redirect to its HTTPS version, and each canonical tag should name the HTTPS address.
COMMON MISTAKEInstalling a certificate but leaving the HTTP version open. If both versions load, visitors and search engines can still land on the insecure one. Redirect every HTTP address to HTTPS.
How to check yours
- Type your address with
http://at the start. You should end up on thehttps://version without doing anything. - Click the icon at the left of the address bar. The browser should say that the connection is secure.
- Check that each internal link and every address in your XML sitemap starts with
https://. - Run the free audit. It checks that the page is served over HTTPS.