HTTPS and SEO: SSL certificates, migration, mixed content and dangerous-site warnings
Published 7 October 20267 min readBy the SmoothSeen editorial team
HTTPS affects SEO more through what visitors see than through rankings. Google announced it as a lightweight signal in 2014 and prefers the HTTPS version of a page as canonical, but what really matters is elsewhere: Chrome warns before opening a site without HTTPS, and an expired certificate or a dangerous-site flag drives away the people who arrive.
Key points
- Google announced HTTPS as a lightweight signal in 2014; today it says that, apart from Core Web Vitals, page experience does not directly help rankings, but it still prefers the HTTPS version as canonical.
- Chrome has labelled HTTP pages "Not secure" since 2018, and Chrome 154 (stable since 22 September 2026) asks by default before opening a public site without HTTPS.
- Moving from http to https is a URL change: single-hop 301 redirects, canonicals, internal links and sitemap on https, and redirects kept for at least a year.
- Browsers block active mixed content (scripts, iframes, fonts) and upgrade images, audio and video to https.
- If Google detects malware or phishing, it shows warnings in results and in the browser; Search Console's Security issues report lets you request a review.
To check it on your own site: SEO audit
On this page
- Does HTTPS improve Google rankings?
- What does change: the browser warning
- The certificate: Let's Encrypt and automatic renewal
- How do you move from http to https without losing traffic?
- Mixed content: what browsers block today
- What happens if Google flags your site as dangerous?
- What SmoothSeen checks
- Frequently asked questions
- What to do next
It is the foundation of the security and trust part of SEO. Here is what Google has published, how to migrate without losing traffic and what to do when the browser or Google puts a warning in front of your site.
Does HTTPS improve Google rankings?
A little, originally; today Google does not present it as a ranking lever. This is what it has published, in order:
- Date
- August 2014
- What Google said
- Starts using HTTPS as a "very lightweight" ranking signal, affecting fewer than 1% of global queries and carrying less weight than high-quality content1
- Date
- April 2023
- What Google said
- Page experience signals had been listed as Core Web Vitals, mobile-friendly, HTTPS and no intrusive interstitials; not all may be used directly for ranking, although all align with success in search2
- Date
- September 2026 (current documentation)
- What Google said
- Beyond Core Web Vitals, other page experience aspects don't directly help a site rank higher; HTTPS remains in Google's self-assessment3
One effect is direct: when a page exists on both http and https, Google prefers the https one as canonical, unless the certificate is invalid, the https page loads insecure dependencies (other than images), it redirects through http or its canonical points to http4. A botched HTTPS setup can lead Google to index the version you do not want.
What does change: the browser warning
Since July 2018, with Chrome 68, Chrome has shown "Not secure" in the address bar for every page served over HTTP5. In October 2025, the Chrome security team announced it would switch on "Always Use Secure Connections" by default, asking the user's permission before the first visit to any public site without HTTPS6. It arrived with Chrome 154, whose stable release came out on 22 September 2026: Chrome now prompts by default when connecting to a site over http7.
For a site without HTTPS, that means part of the visits it earns from Google meet a warning before they see the page. The ranking may be unchanged; the click is lost all the same.
The certificate: Let's Encrypt and automatic renewal
Let's Encrypt is a certificate authority that issues free certificates with automated renewal. Its certificates currently last 90 days, and that is getting shorter8:
- Date
- 13 May 2026
- Let's Encrypt certificates
- Opt-in
tlsserverprofile with 45-day certificates
- Date
- 10 Feb 2027
- Let's Encrypt certificates
- Default profile moves to 64 days
- Date
- 16 Feb 2028
- Let's Encrypt certificates
- Default profile moves to 45 days
This is not an isolated decision: in April 2025 the CA/Browser Forum approved a phased cut in the maximum validity of all public certificates, from 398 days to 47, between March 2026 and March 20299. The practical consequence is simple: renewal has to be automatic. Let's Encrypt warns that renewing at a fixed 60-day interval will no longer be enough and recommends that your client supports ARI, the mechanism that tells it when to renew8.
How do you move from http to https without losing traffic?
Google treats the switch from http to https as a site move with URL changes10. Follow this order:
- A certificate on every variant that gets visits: with and without
www, and every subdomain in use. - Permanent server-side redirects (301 or 308) from each http URL to its https equivalent, in a single hop. Google confirms that permanent redirects do not cause a loss in PageRank10.
- Canonicals on https. Every new page with a self-referencing
rel="canonical"on https. - Internal links and resources on https, so you neither depend on redirects nor trigger mixed content.
- A new sitemap with the https URLs, submitted in Search Console. Verify the https property, or better still a Domain property.
- Redirects for at least a year, and ideally for good10.
- HSTS last, once everything else works, as explained in the guide to HTTP security headers.
Expect some fluctuation: Google warns that, on a medium-sized site, it can take a few weeks before it shows the new URLs instead of the old ones10. To check the redirects (replace example.com with your domain):
# Every variant should end at the same https URL with a single 301
for u in http://example.com/ http://www.example.com/ https://example.com/; do
echo "== $u"
curl -sIL "$u" | grep -iE "^(HTTP|location)"
doneAfterwards, Search Console's HTTPS report shows how many indexed URLs are still on http and why their https version was not indexed; ideally there should be none11. Redirect chains and canonicals are covered in more depth in the guide to technical SEO.
Mixed content: what browsers block today
Mixed content is when a page loaded over HTTPS requests resources over HTTP. MDN now splits it into two groups12:
- Type
- Upgradable (formerly "passive")
- Examples
<img>,<audio>,<video>and<source>withsrc, CSS background images- What the browser does
- Requests it over https; if that fails, the request proceeds as normal. If the host is an IP address, it is blocked
- Type
- Blockable (formerly "active")
- Examples
<script>,<link>,<iframe>,fetch(), web fonts,<img>withsrcsetor inside<picture>- What the browser does
- Blocks it
In practice: a third-party script linked over http does not run, a font fails to load or an iframe stays blank, and the browser console logs it. Remember too that Google may not choose your https page as canonical if it loads insecure dependencies other than images4. The fix is to change the URLs to https in your code and database; the CSP directive upgrade-insecure-requests tells the browser to upgrade every request to https, blockable ones included12, and works as a safety net while you fix it.
What happens if Google flags your site as dangerous?
Google Safe Browsing protects over five billion devices by warning people before they visit sites with malware, unwanted software or social engineering such as phishing; Chrome and other browsers, Google Search and Gmail all use it13. Affected pages can appear with a warning label in search results or behind an interstitial warning page in the browser14.
If it happens to you:
- Open Search Console's Security issues report: it names the type of problem (hacked content, malware, deceptive pages, harmful downloads) and gives example URLs14.
- Fix all the issues on all pages; fixing only some pages will not earn even a partial return to search results14.
- Select Request review and explain the problem, what you did and the outcome. A review takes from a few days to a few weeks14.
To check any domain's status without Search Console, use Safe Browsing's Site Status tool in Google's Transparency Report13. Business applications can ask the same question through Web Risk, Google's API that checks URLs against its constantly updated lists of unsafe web resources15.
What SmoothSeen checks
Disclosure: this blog belongs to SmoothSeen. In the security and trust category of its SEO analysis, SmoothSeen checks that the page is served over HTTPS, detects resources loaded over http on an https page and queries Google Web Risk to see whether the URL is flagged as dangerous. The same category shows the header grade from Mozilla's HTTP Observatory and reviews SPF and DMARC, as explained in the guide to SPF, DKIM and DMARC.
Frequently asked questions
Does a paid SSL certificate rank better than a free Let's Encrypt one?
Google has never said the type of certificate makes a difference. What it asks is that the certificate is valid: with an invalid one, Google may prefer the http version as canonical. A paid certificate may include company validation or support, but the browser shows a secure connection just the same with a free certificate that is properly installed and renewed.
Will I lose rankings when I move from http to https?
There may be fluctuation while Google recrawls the site: on a medium-sized site, a few weeks before it shows the new URLs. Permanent redirects do not lose PageRank, so a well-executed migration (single-hop 301s, canonicals, internal links and sitemap on https) should leave no lasting damage. What does hurt is leaving chains or URLs without redirects.
I have a certificate, so why does Chrome say the page is not secure?
It is almost always mixed content: the https page loads a resource over http, or a form submits its data to an http address. Open Chrome's developer tools, check the console and the security panel, find the resource and change its URL to https. It can also be an expired certificate or one issued for a different domain name.
How long does Google take to remove a dangerous-site warning?
According to Search Console Help, a security review takes from a few days to a few weeks after you request it. You get an email when you submit it and another with the decision, and you should not resubmit in the meantime. Before you ask, make sure the problem is fixed on every affected page.
What to do next
Run the curl loop against your domain and check that every variant reaches the same https URL in a single hop; then open Chrome's console on your main templates and look for mixed content warnings. To see how security fits with the rest of an analysis, carry on with the guide to what SEO is.
Sources
- 1HTTPS as a ranking signal, Google Search Central Blog, accessed 7 October 2026.
- 2The role of page experience in creating helpful content, Google Search Central Blog, accessed 7 October 2026.
- 3Understanding page experience in Google Search results, Google Search Central, updated 22 September 2026.
- 4How to specify a canonical URL with rel=canonical and other methods, Google Search Central, updated 10 July 2026.
- 5A secure web is here to stay, Chromium Blog, accessed 7 October 2026.
- 6HTTPS by default, Google (Chrome Security Team), accessed 7 October 2026.
- 7Chrome 154: release notes, Chrome for Developers, updated 22 September 2026.
- 8Decreasing Certificate Lifetimes to 45 Days, Let's Encrypt, accessed 7 October 2026.
- 9Ballot SC081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods, CA/Browser Forum, accessed 7 October 2026.
- 10Site moves and migrations, Google Search Central, updated 20 August 2026.
- 11HTTPS report, Search Console Help, accessed 7 October 2026.
- 12Mixed content, MDN, updated 15 August 2026.
- 13Google Safe Browsing, Google, accessed 7 October 2026.
- 14Security issues report, Search Console Help, accessed 7 October 2026.
- 15Overview of Web Risk, Google Cloud, updated 7 October 2026.
How to cite this article
SmoothSeen. (2026, October 7). HTTPS and SEO: SSL certificates, migration, mixed content and dangerous-site warnings. https://smoothseen.com/en/blog/https-seo/
Keep reading
What is SEO? How search engine optimisation works and how to improve it in 2026
What SEO is, how Google decides which pages to show and a prioritised checklist to improve your rankings with free tools.
.htaccess force HTTPS: redirect to https, enable HSTS and add security headers in Apache
How to force HTTPS in .htaccess or an Apache VirtualHost, roll out HSTS safely and add security headers. Every snippet tested on Apache 2.4.69.
.htaccess gzip and Brotli: browser caching and blocking AI bots in Apache
How to enable gzip and Brotli, set browser caching and block AI training bots in Apache .htaccess without dropping out of ChatGPT search. Tested.