27 July 2026

HTTPS vs HTTP: Does SSL Still Affect Your SEO Rankings in 2026?

Anjan Luthra
Anjan Luthra

Managing Partner · 8 min read

Key Takeaways

  • HTTP (HyperText Transfer Protocol) is the communication layer between a browser and a web server.
  • Google's original 2014 announcement described HTTPS as a "lightweight" signal — one that affected fewer than 1% of queries at the time and carried less weight than content quality signals.
  • The direct ranking signal is a minor factor.
  • This is the section most guides omit, and it is the most practically important for anyone planning an HTTP-to-HTTPS move.
  • An expired TLS certificate takes a site effectively offline for most users — browsers block access entirely, not just flag a warning.
  • Yes, but it functions as a threshold rather than a competitive differentiator.
  • If your site is still on HTTP, treat migration as a technical debt item with a hard deadline rather than an optional improvement.

Google confirmed HTTPS as a ranking signal back in 2014. Twelve years later, most sites have migrated — yet questions about the HTTPS vs HTTP SEO impact persist, particularly among teams inheriting legacy infrastructure or planning a site rebuild. The signal itself is real, but its weight in the ranking algorithm is often misunderstood, and the indirect effects on your organic performance are rarely discussed with any precision.

This article unpacks what HTTPS actually does for your rankings, what it does not do, and where the real risk lies for sites still running on HTTP in 2026.

If you're looking for expert help in this area, explore how Indexed's technical SEO services can drive measurable results for your business.

What HTTPS Actually Is — and What It Is Not

HTTP (HyperText Transfer Protocol) is the communication layer between a browser and a web server. HTTPS adds TLS (Transport Layer Security) encryption on top of that connection, which serves three purposes: it encrypts data in transit, it authenticates the server's identity, and it ensures the integrity of the data exchanged.

A TLS certificate — commonly called an SSL certificate, though SSL is technically an older standard — is what enables HTTPS. When a browser connects to an HTTPS site, the server presents its certificate, the browser verifies it against a trusted certificate authority, and an encrypted session begins.

What HTTPS Does Not Do

HTTPS secures the connection between the user and the server. It does not secure the server itself, prevent malware on the site, protect against poor coding practices, or guarantee the site is trustworthy in any editorial sense. A phishing site can — and frequently does — have a valid TLS certificate and display the padlock icon. Security teams conflate these things regularly; SEOs should not.

The HTTPS vs HTTP SEO Impact: Reading the Ranking Signal Honestly

Google's original 2014 announcement described HTTPS as a "lightweight" signal — one that affected fewer than 1% of queries at the time and carried less weight than content quality signals. That framing has never fundamentally changed.

By 2026, the signal's practical differentiation value is close to zero for most competitive queries. If your competitors are all on HTTPS — which they almost certainly are — then being on HTTPS gives you no ranking advantage over them. The signal functions more like a minimum requirement than a performance lever. Not having it is a liability; having it is simply table stakes.

Where the Signal Still Has Practical Bite

There are specific scenarios where HTTP genuinely holds a site back in search:

  • Mixed-content warnings: If your main pages load over HTTPS but pull in resources — scripts, images, iframes — over HTTP, browsers flag these as mixed content. Chrome may block them entirely, breaking page functionality and Core Web Vitals scores.
  • Referrer data loss: When a user navigates from an HTTPS page to an HTTP page, the referrer header is stripped by browser security policy. This means your analytics under-reports organic and referral traffic for HTTP destinations, which distorts channel attribution across your reporting.
  • Chrome browser warnings: Since Chrome 68, HTTP pages are marked "Not Secure" in the address bar. For any page where a user enters data — forms, checkout, login — this warning demonstrably reduces trust and conversion rates, which in turn affects the behavioural signals that correlate with ranking performance.

Free · No obligation

Find out what your site is losing in organic revenue.

In a free Revenue Gap Analysis, we show you exactly what's holding your rankings back — and what fixing it is worth in real revenue.

See my revenue opportunity →

The Indirect Effects Nobody Talks About

The direct ranking signal is a minor factor. The indirect effects are where HTTP genuinely costs sites organic performance — and most coverage of this topic stops at the signal announcement.

HTTP/2 and Page Speed

HTTP/2 — the protocol version that enables multiplexing (loading multiple resources simultaneously over a single connection) and header compression — is only available over HTTPS in all major browsers. HTTP/1.1, which most HTTP-only sites are effectively stuck on, loads resources sequentially. For pages with many assets, this creates meaningful latency differences that surface directly in your Largest Contentful Paint and Time to First Byte scores — both Core Web Vitals metrics that Google uses in ranking.

If your site is on HTTP and you are wondering why your Core Web Vitals scores underperform against competitors with ostensibly similar hosting, the protocol version is a plausible contributor.

Crawl Budget and Canonicalisation

Many legacy HTTP sites exist alongside a partially migrated HTTPS version, with neither a clean 301 redirect chain nor a consistent canonical tag strategy. Googlebot then encounters both the HTTP and HTTPS variants of the same URLs, splitting crawl budget and creating duplicate content signals. This is not a hypothetical edge case — it is a common audit finding on sites that "did the migration" years ago without verifying the redirect implementation rigorously.

The Migration Risks That Create More SEO Damage Than HTTP Itself

This is the section most guides omit, and it is the most practically important for anyone planning an HTTP-to-HTTPS move.

A poorly executed migration can — and does — cause more ranking damage than simply staying on HTTP in the short term. The risks to manage carefully:

  • Redirect chains: HTTP → HTTPS should be a single 301 redirect. If your CMS or hosting adds an intermediate step (e.g., HTTP → non-www HTTPS → www HTTPS), each hop dilutes link equity and adds latency. Audit the chain before and after migration.
  • Internal links not updated: If your CMS still generates internal links pointing to HTTP URLs, every internal link becomes a redirect. This is measurable overhead for crawling and page load, and it signals to Google that the migration was incomplete.
  • Backlinks not updated: You cannot force third parties to update their links, but your 301s should handle them. The concern is redirect chains: if a backlink points to an old HTTP URL that then hits a second redirect (e.g., to a new URL path), equity loss compounds.
  • Search Console property separation: Google Search Console treats HTTP and HTTPS as distinct properties. If you migrate without adding and verifying the HTTPS property and setting it as the primary, you lose continuity in your performance data and potentially miss crawl error alerts.
  • HSTS configuration: HTTP Strict Transport Security (HSTS) tells browsers to always connect via HTTPS, preventing downgrade attacks. Misconfiguring HSTS — particularly setting an overly long max-age without testing — can lock users out if you ever need to temporarily serve HTTP. Implement it, but test it.

Certificate Maintenance: The Ongoing SEO Risk After Migration

An expired TLS certificate takes a site effectively offline for most users — browsers block access entirely, not just flag a warning. This is a scenario that surfaces in agency audits with uncomfortable regularity: a site migrated to HTTPS three years ago, the certificate was on auto-renewal, auto-renewal failed, and the site was inaccessible for 48 hours before anyone noticed.

From a search perspective, a prolonged site outage causes Googlebot to drop URLs from the index. Recovering index coverage after a multi-day outage is not immediate — it typically takes several crawl cycles, which at normal crawl frequencies means weeks, not days.

Certificate management is therefore a live SEO risk, not a one-time migration task. Monitoring certificate expiry via uptime tools or services like SSL Labs should be part of your standard site health checks.

See the system

The Full-Stack Search Method.

Seven compounding pillars that turn search into your highest ROI channel. See exactly how we build organic growth that lasts.

See the full methodology →

FAQ

Is HTTPS still a Google ranking factor in 2026?

Yes, but it functions as a threshold rather than a competitive differentiator. Google confirmed the signal in 2014 and has not removed it. In practice, because nearly all indexed sites now use HTTPS, the signal has no meaningful separating power in competitive niches. The greater risk for sites remaining on HTTP is the indirect effects: browser warnings, protocol limitations, and analytics data distortion.

Will switching to HTTPS boost my rankings?

For sites still on HTTP, migrating correctly should remove a minor ranking penalty and eliminate the "Not Secure" browser warning that suppresses click-through rates. Do not expect a dramatic rankings jump from the protocol change alone — content relevance, backlink authority, and Core Web Vitals will have far greater influence. What you should expect is the removal of a ceiling and an improvement in crawling efficiency if your internal linking is cleaned up simultaneously.

Does a free Let's Encrypt certificate work as well as a paid SSL certificate for SEO?

Yes. Google's ranking signal does not differentiate between certificate types or issuing authorities. A Let's Encrypt certificate, which is free and widely supported, provides the same HTTPS signal as an expensive extended validation certificate. The practical difference between certificate tiers is the level of identity verification displayed to users in some browsers — not the SEO signal.

My site is on HTTPS but I'm seeing HTTP URLs in Google Search Console — what does that mean?

It typically means either your 301 redirects are incomplete, your internal links still reference HTTP URLs, or your XML sitemap contains HTTP addresses. Check your sitemap first — it should list only canonical HTTPS URLs. Then audit your internal link output from your CMS, and use Search Console's URL Inspection tool on the HTTP variants to confirm they return a 301 and not a 200 status code.

What to Do This Week

If your site is already on HTTPS, three concrete checks are worth doing in the next five working days:

  • Check your certificate expiry date and confirm auto-renewal is active and monitored. Log in to your hosting provider or certificate authority dashboard and verify the next renewal date. Add a calendar reminder 30 days before expiry as a backstop.
  • Audit for mixed content using your browser's developer console (Network tab, filter by HTTP) on your five highest-traffic pages. Any resources loading over HTTP need to be updated to HTTPS references or switched to protocol-relative URLs.
  • Verify your redirect chain for your homepage using a tool like httpstatus.io. Enter your HTTP root URL and confirm it resolves in a single 301 to your canonical HTTPS URL — no intermediate hops.
  • Cross-check your Search Console properties. Confirm you have an active, verified HTTPS property and that your sitemap is submitted within it — not within a legacy HTTP property.

If your site is still on HTTP, treat migration as a technical debt item with a hard deadline rather than an optional improvement. The direct ranking penalty is modest; the accumulation of indirect effects — Core Web Vitals, analytics distortion, browser warnings — compounds over time and becomes progressively harder to attribute correctly.

Anjan Luthra

Written by

Anjan Luthra

Managing Partner, Indexed

Anjan Luthra is Managing Partner at Indexed. He has spent over a decade inside high-growth companies building organic search into their primary acquisition channel, and writes about SEO strategy, AI search, and revenue a…

Share

Get SEO insights that actually move the needle.

Strategy, AI search, and growth tactics from the Indexed team — straight to your inbox.

Unsubscribe anytime. No spam.