Does HTTPS Affect SEO?

The direct ranking effect of HTTPS is small and settled. The indirect effects, on trust, browser features and referral data, are where the real cost of staying on HTTP lives.

Does HTTPS Affect SEO? — Troiana insight cover

In short

Yes, slightly and directly: Google confirmed HTTPS as a lightweight ranking signal in 2014, and with the overwhelming majority of pages now secure it functions as a baseline expectation rather than a boost. The larger effects are indirect: browsers label HTTP pages 'Not Secure' and block modern features on them, visitors trust and convert on them less, and HTTP sites lose referrer data. A badly executed HTTPS migration, with missing redirects or mixed content, can cost more rankings than staying on HTTP would; done properly, it costs nothing and removes a liability.

The direct signal

Google announced in August 2014 that it would use HTTPS as a ranking signal, describing it as lightweight, affecting fewer than one percent of queries, and carrying less weight than content quality. That description has never been revised upward. In the years since, the signal has been confirmed as still present, still light, and used mainly as a tiebreaker between otherwise similar pages.

So the honest answer to the direct question is: yes, a little. A page on HTTPS has a small edge over an identical page on HTTP. It will not lift a weak page above a strong one.

Why it is now a baseline, not a boost

When the signal was introduced, most of the web was on HTTP, and moving early was a small advantage. Today over 95% of page loads in Chrome are over HTTPS. Being secure no longer distinguishes a site; being insecure does. The ranking signal has become one of several ways an HTTP site is at a mild disadvantage, and the disadvantage compounds with the indirect effects.

The indirect effects, which are larger

The browser warning. Chrome, Firefox, Safari and Edge mark HTTP pages as "Not Secure" in the address bar, and show a stronger warning when a visitor starts typing into a form. Visitors leave, and visitors who stay convert less. That is a behavioural effect Google's systems can observe and one that shows up in every other metric.

Blocked features. Geolocation, service workers, push notifications, the payment request API, camera and microphone access, and HTTP/2 in most browsers are unavailable on insecure pages. Several of these affect speed and Core Web Vitals directly.

Lost referrer data. When a visitor moves from an HTTPS page to an HTTP page, browsers strip the referrer. An HTTP site sees traffic from secure sites, which is now nearly all of them, as "direct", and cannot attribute it. Its analytics are worse than an HTTPS site's for the same visitors.

Crawling and indexing. Google prefers HTTPS URLs as canonical when both versions exist, and will index the secure version. A site that serves both without redirects is splitting itself in two.

Trust signals for E-E-A-T. The quality rater guidelines mention site security among the things that affect a page's trustworthiness. A site asking for personal data over HTTP is a specific negative.

Where migrations go wrong

The move to HTTPS is, technically, a site migration: every URL changes. Done carelessly, it loses rankings that took years to earn, which is the source of the myth that HTTPS hurts SEO. The failures:

  • No redirects, or 302s instead of 301s. Every HTTP URL must permanently redirect to its exact HTTPS equivalent. Redirecting everything to the homepage, or using temporary redirects, throws away the old URLs' signals.
  • Redirect chains. HTTP to HTTPS to www to a trailing-slash version. Each hop wastes crawl and dilutes signals; the chain should be one hop.
  • Mixed content. Images, scripts or stylesheets still loaded over HTTP, which browsers block or warn about and which breaks the page.
  • Internal links, canonicals and sitemaps still pointing at HTTP. Every internal reference should use the secure URL; a canonical tag pointing at the HTTP version tells Google the wrong page is preferred.
  • Forgetting Search Console. The HTTPS version is a separate property; add it, submit the new sitemap, and expect a few weeks of fluctuation while Google reprocesses.
  • Certificate problems such as expiry, wrong hostname or a chain that some devices do not trust. Any of these blocks the site entirely for affected visitors.

Done properly, a migration causes a brief wobble and then nothing. A website migration checklist covers the same steps, because the same discipline applies.

The cost of doing it

Certificates are free through Let's Encrypt on virtually every host and platform, and renewal is automatic. The work is the redirect rule, the search-and-replace of internal URLs, the sitemap and Search Console updates, and a check for mixed content. For a small site, an afternoon. For a large site with years of content, a planned project, but still a bounded one.

The short answer

HTTPS affects SEO a little directly and a good deal indirectly, and in 2026 it is not a decision so much as a prerequisite. If a site is still on HTTP, moving it is one of the few remaining changes that is free, quick and unambiguously positive, provided the redirects are right. If you are planning the move on a site with a lot of history, book a call and we will make sure nothing is lost on the way.

Common questions

Is HTTPS a Google ranking factor?

Yes. Google confirmed it as a ranking signal in 2014, describing it as lightweight and less important than content. It mainly acts as a tiebreaker. With almost all pages now secure, it works as a baseline expectation; HTTP sites are at a mild disadvantage rather than HTTPS sites enjoying a boost.

How much does HTTPS improve rankings?

Very little on its own; Google has never described the signal as more than lightweight. The measurable gains come indirectly: fewer visitors bouncing from the browser's 'Not Secure' warning, better conversion, access to browser features that improve speed, and intact referrer data. Do not expect a ranking jump from the certificate alone.

Can switching to HTTPS hurt my SEO?

Only if the migration is botched. Missing or temporary redirects, redirect chains, mixed content, canonical tags still pointing at HTTP, and an unsubmitted sitemap can each cost rankings. With one-hop 301 redirects from every HTTP URL to its exact HTTPS equivalent and updated internal links, the move causes a brief fluctuation and no lasting loss.

Do I need HTTPS if my website has no forms or logins?

Yes. Browsers label every HTTP page 'Not Secure' regardless of content, strip referrer data when secure sites link to it, and withhold features such as HTTP/2 that improve speed. Certificates are free and automatic on almost every host, so there is no longer a cost to weigh against the benefits.

How long does it take for Google to recognise an HTTPS migration?

Google typically reprocesses a small site within a few weeks and a large one within a couple of months, with some ranking fluctuation in between. Adding the HTTPS property in Search Console, submitting the new sitemap and using permanent redirects shortens the period. Keep the redirects in place indefinitely.

Have something worth building right?