Skip to content

HTTPS and SEO: SSL certificates, migration, mixed content and dangerous-site warnings

Published 7 October 20267 min readBy the SmoothSeen editorial team

HTTPS affects SEO more through what visitors see than through rankings. Google announced it as a lightweight signal in 2014 and prefers the HTTPS version of a page as canonical, but what really matters is elsewhere: Chrome warns before opening a site without HTTPS, and an expired certificate or a dangerous-site flag drives away the people who arrive.

Key points

  • Google announced HTTPS as a lightweight signal in 2014; today it says that, apart from Core Web Vitals, page experience does not directly help rankings, but it still prefers the HTTPS version as canonical.
  • Chrome has labelled HTTP pages "Not secure" since 2018, and Chrome 154 (stable since 22 September 2026) asks by default before opening a public site without HTTPS.
  • Moving from http to https is a URL change: single-hop 301 redirects, canonicals, internal links and sitemap on https, and redirects kept for at least a year.
  • Browsers block active mixed content (scripts, iframes, fonts) and upgrade images, audio and video to https.
  • If Google detects malware or phishing, it shows warnings in results and in the browser; Search Console's Security issues report lets you request a review.

To check it on your own site: SEO audit

On this page

It is the foundation of the security and trust part of SEO. Here is what Google has published, how to migrate without losing traffic and what to do when the browser or Google puts a warning in front of your site.

Does HTTPS improve Google rankings?

A little, originally; today Google does not present it as a ranking lever. This is what it has published, in order:

Date
August 2014
What Google said
Starts using HTTPS as a "very lightweight" ranking signal, affecting fewer than 1% of global queries and carrying less weight than high-quality content1
Date
April 2023
What Google said
Page experience signals had been listed as Core Web Vitals, mobile-friendly, HTTPS and no intrusive interstitials; not all may be used directly for ranking, although all align with success in search2
Date
September 2026 (current documentation)
What Google said
Beyond Core Web Vitals, other page experience aspects don't directly help a site rank higher; HTTPS remains in Google's self-assessment3

One effect is direct: when a page exists on both http and https, Google prefers the https one as canonical, unless the certificate is invalid, the https page loads insecure dependencies (other than images), it redirects through http or its canonical points to http4. A botched HTTPS setup can lead Google to index the version you do not want.

What does change: the browser warning

Since July 2018, with Chrome 68, Chrome has shown "Not secure" in the address bar for every page served over HTTP5. In October 2025, the Chrome security team announced it would switch on "Always Use Secure Connections" by default, asking the user's permission before the first visit to any public site without HTTPS6. It arrived with Chrome 154, whose stable release came out on 22 September 2026: Chrome now prompts by default when connecting to a site over http7.

For a site without HTTPS, that means part of the visits it earns from Google meet a warning before they see the page. The ranking may be unchanged; the click is lost all the same.

The certificate: Let's Encrypt and automatic renewal

Let's Encrypt is a certificate authority that issues free certificates with automated renewal. Its certificates currently last 90 days, and that is getting shorter8:

Date
13 May 2026
Let's Encrypt certificates
Opt-in tlsserver profile with 45-day certificates
Date
10 Feb 2027
Let's Encrypt certificates
Default profile moves to 64 days
Date
16 Feb 2028
Let's Encrypt certificates
Default profile moves to 45 days

This is not an isolated decision: in April 2025 the CA/Browser Forum approved a phased cut in the maximum validity of all public certificates, from 398 days to 47, between March 2026 and March 20299. The practical consequence is simple: renewal has to be automatic. Let's Encrypt warns that renewing at a fixed 60-day interval will no longer be enough and recommends that your client supports ARI, the mechanism that tells it when to renew8.

How do you move from http to https without losing traffic?

Google treats the switch from http to https as a site move with URL changes10. Follow this order:

  1. A certificate on every variant that gets visits: with and without www, and every subdomain in use.
  2. Permanent server-side redirects (301 or 308) from each http URL to its https equivalent, in a single hop. Google confirms that permanent redirects do not cause a loss in PageRank10.
  3. Canonicals on https. Every new page with a self-referencing rel="canonical" on https.
  4. Internal links and resources on https, so you neither depend on redirects nor trigger mixed content.
  5. A new sitemap with the https URLs, submitted in Search Console. Verify the https property, or better still a Domain property.
  6. Redirects for at least a year, and ideally for good10.
  7. HSTS last, once everything else works, as explained in the guide to HTTP security headers.

Expect some fluctuation: Google warns that, on a medium-sized site, it can take a few weeks before it shows the new URLs instead of the old ones10. To check the redirects (replace example.com with your domain):

# Every variant should end at the same https URL with a single 301
for u in http://example.com/ http://www.example.com/ https://example.com/; do
  echo "== $u"
  curl -sIL "$u" | grep -iE "^(HTTP|location)"
done

Afterwards, Search Console's HTTPS report shows how many indexed URLs are still on http and why their https version was not indexed; ideally there should be none11. Redirect chains and canonicals are covered in more depth in the guide to technical SEO.

Mixed content: what browsers block today

Mixed content is when a page loaded over HTTPS requests resources over HTTP. MDN now splits it into two groups12:

Type
Upgradable (formerly "passive")
Examples
<img>, <audio>, <video> and <source> with src, CSS background images
What the browser does
Requests it over https; if that fails, the request proceeds as normal. If the host is an IP address, it is blocked
Type
Blockable (formerly "active")
Examples
<script>, <link>, <iframe>, fetch(), web fonts, <img> with srcset or inside <picture>
What the browser does
Blocks it

In practice: a third-party script linked over http does not run, a font fails to load or an iframe stays blank, and the browser console logs it. Remember too that Google may not choose your https page as canonical if it loads insecure dependencies other than images4. The fix is to change the URLs to https in your code and database; the CSP directive upgrade-insecure-requests tells the browser to upgrade every request to https, blockable ones included12, and works as a safety net while you fix it.

What happens if Google flags your site as dangerous?

Google Safe Browsing protects over five billion devices by warning people before they visit sites with malware, unwanted software or social engineering such as phishing; Chrome and other browsers, Google Search and Gmail all use it13. Affected pages can appear with a warning label in search results or behind an interstitial warning page in the browser14.

If it happens to you:

  1. Open Search Console's Security issues report: it names the type of problem (hacked content, malware, deceptive pages, harmful downloads) and gives example URLs14.
  2. Fix all the issues on all pages; fixing only some pages will not earn even a partial return to search results14.
  3. Select Request review and explain the problem, what you did and the outcome. A review takes from a few days to a few weeks14.

To check any domain's status without Search Console, use Safe Browsing's Site Status tool in Google's Transparency Report13. Business applications can ask the same question through Web Risk, Google's API that checks URLs against its constantly updated lists of unsafe web resources15.

What SmoothSeen checks

Disclosure: this blog belongs to SmoothSeen. In the security and trust category of its SEO analysis, SmoothSeen checks that the page is served over HTTPS, detects resources loaded over http on an https page and queries Google Web Risk to see whether the URL is flagged as dangerous. The same category shows the header grade from Mozilla's HTTP Observatory and reviews SPF and DMARC, as explained in the guide to SPF, DKIM and DMARC.

Frequently asked questions

Does a paid SSL certificate rank better than a free Let's Encrypt one?

Google has never said the type of certificate makes a difference. What it asks is that the certificate is valid: with an invalid one, Google may prefer the http version as canonical. A paid certificate may include company validation or support, but the browser shows a secure connection just the same with a free certificate that is properly installed and renewed.

Will I lose rankings when I move from http to https?

There may be fluctuation while Google recrawls the site: on a medium-sized site, a few weeks before it shows the new URLs. Permanent redirects do not lose PageRank, so a well-executed migration (single-hop 301s, canonicals, internal links and sitemap on https) should leave no lasting damage. What does hurt is leaving chains or URLs without redirects.

I have a certificate, so why does Chrome say the page is not secure?

It is almost always mixed content: the https page loads a resource over http, or a form submits its data to an http address. Open Chrome's developer tools, check the console and the security panel, find the resource and change its URL to https. It can also be an expired certificate or one issued for a different domain name.

How long does Google take to remove a dangerous-site warning?

According to Search Console Help, a security review takes from a few days to a few weeks after you request it. You get an email when you submit it and another with the decision, and you should not resubmit in the meantime. Before you ask, make sure the problem is fixed on every affected page.

What to do next

Run the curl loop against your domain and check that every variant reaches the same https URL in a single hop; then open Chrome's console on your main templates and look for mixed content warnings. To see how security fits with the rest of an analysis, carry on with the guide to what SEO is.

Sources

  1. 1HTTPS as a ranking signal, Google Search Central Blog, accessed 7 October 2026.
  2. 2The role of page experience in creating helpful content, Google Search Central Blog, accessed 7 October 2026.
  3. 3Understanding page experience in Google Search results, Google Search Central, updated 22 September 2026.
  4. 4How to specify a canonical URL with rel=canonical and other methods, Google Search Central, updated 10 July 2026.
  5. 5A secure web is here to stay, Chromium Blog, accessed 7 October 2026.
  6. 6HTTPS by default, Google (Chrome Security Team), accessed 7 October 2026.
  7. 7Chrome 154: release notes, Chrome for Developers, updated 22 September 2026.
  8. 8Decreasing Certificate Lifetimes to 45 Days, Let's Encrypt, accessed 7 October 2026.
  9. 9Ballot SC081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods, CA/Browser Forum, accessed 7 October 2026.
  10. 10Site moves and migrations, Google Search Central, updated 20 August 2026.
  11. 11HTTPS report, Search Console Help, accessed 7 October 2026.
  12. 12Mixed content, MDN, updated 15 August 2026.
  13. 13Google Safe Browsing, Google, accessed 7 October 2026.
  14. 14Security issues report, Search Console Help, accessed 7 October 2026.
  15. 15Overview of Web Risk, Google Cloud, updated 7 October 2026.

How to cite this article

SmoothSeen. (2026, October 7). HTTPS and SEO: SSL certificates, migration, mixed content and dangerous-site warnings. https://smoothseen.com/en/blog/https-seo/

Who writes this

SmoothSeen is a website audit tool that measures visibility in search engines and AI assistants and delivers reports under the agency's own brand.

This blog belongs to SmoothSeen: when an article discusses the product, it does so knowing the product is ours. Third-party figures link to their original source.

Change history

  • First version.

Keep reading

HTTPS and SEO: SSL certificates, migration and mixed content