Skip to main content
Migration guide

How to move your site to HTTPS

The move itself takes an afternoon. What costs sites traffic is the order the steps are done in — a redirect switched on before the mixed content is cleared, or a certificate nobody renews. Here is the sequence that avoids both.

Why the move is no longer optional

HTTPS stopped being an advantage and became the baseline. These are the four things that change when a site is served over it.

  • Nobody reads the traffic

    Logins, form data, cookies and the pages themselves are encrypted between the visitor and your server, so a shared Wi-Fi network or a hop along the route cannot read or rewrite them.

  • Nobody rewrites it either

    Plain HTTP can be modified in transit — injected adverts and rewritten download links are the usual result. A certificate makes that tampering detectable.

  • Search engines expect it

    Google has treated HTTPS as a ranking signal since 2014. It is a small one on its own, but it now sits alongside page experience metrics that HTTPS is a precondition for.

  • The modern web requires it

    HTTP/2, HTTP/3, service workers, geolocation, the camera and microphone APIs, and most payment integrations refuse to run on an insecure origin.

The migration, step by step

Work through them in order. Steps 1 to 4 can be done on a staging copy; step 6 is the one that makes the change public.

  1. Take stock of every name you serve

    List every hostname the site answers on — the bare domain, www, and any subdomain such as shop, blog or api. The certificate has to cover all of them, and a name found after the migration means reissuing. Note any third-party scripts, fonts and images you embed as well; they are what step 4 is about.

  2. Choose a certificate that covers them

    One name needs a single-domain certificate, a set of subdomains needs a wildcard, and unrelated domains need a multi-domain one. Validation level is a separate decision: DV proves control of the domain and issues in minutes, OV and EV also verify the company behind it.

    See certificates and prices

  3. Generate the CSR, install the certificate, verify the chain

    Create the key and the certificate signing request on the server that will hold them, and keep the private key there. After installing, check the chain rather than trusting the browser you happen to use — a missing intermediate is invisible in desktop Chrome and fatal on older Android.

    CSR generator SSL checker Chain fixer

  4. Clear the mixed content

    A page served over HTTPS that pulls in an http:// resource is mixed content, and browsers do more than warn: scripts, stylesheets and iframes are blocked outright, while images, audio and video are silently retried over HTTPS and fail to load if the host does not serve them there. Fix the references in templates, in the database and in your CSS. When something still refuses to load, read the failed request in the browser's network tab — the host it names tells you whether you missed an http:// URL, the host has no HTTPS at all, or hotlink protection needs the https:// form of your domain added to its allowed list.

  5. Update internal links and canonical tags

    Internal links, canonical tags, hreflang tags, Open Graph URLs and structured data should all point at the https:// version. Relying on the redirect for internal links works, but spends a round trip on every click and leaves the old URL as the one you publish.

  6. Redirect HTTP to HTTPS with a 301, then add HSTS

    A permanent 301 from every HTTP URL to its HTTPS twin passes the accumulated ranking signals across and makes the new address the canonical one. Once you have run the site on HTTPS without problems for a while, add the Strict-Transport-Security header so browsers stop trying HTTP at all — start with a short max-age, because the header is hard to take back.

  7. Tell the search engines

    Add the HTTPS site as a separate property in Google Search Console and Bing Webmaster Tools, submit a sitemap whose URLs are all https://, and make sure robots.txt is not blocking the new pages. Do not remove the HTTP property: it is where you watch the old URLs being dropped. If you keep a disavow list, upload it to the HTTPS property as well — Search Console holds one list per URL-prefix property and carries nothing across (the tool does not apply to Domain properties).

  8. Watch the first weeks, then keep the certificate renewed

    Expect indexing to move gradually rather than overnight; a brief dip while both versions are known is normal. Then diarise the expiry date. An expired certificate is a full-page browser warning, and it is the most common way a site that moved to HTTPS successfully goes down a year later.

Before you call it done

Six checks that catch what the steps above usually miss.

  • The certificate chain is complete and the certificate matches the private key on every server behind the load balancer.
  • Every hostname resolves over HTTPS, including the www and non-www forms.
  • No page loads an http:// resource — check the article pages and the checkout, not only the home page.
  • Every HTTP URL answers with a 301, not a 302, and lands on the matching HTTPS page rather than the home page.
  • The sitemap, robots.txt, canonical tags and structured data all carry https:// URLs.
  • The expiry date is in a calendar owned by a person who still works here, or renewal is automated.

Questions that come up during the move

The browser says the connection is not fully secure. Why?

Almost always mixed content: the page itself is served over HTTPS but something on it — an image, a font, a tracking script — is requested over HTTP. Do not judge this by the icon next to the address: Chrome replaced the padlock with a settings icon for every site in version 117, and the browsers that kept a padlock each draw it differently. The developer console names the resource that was blocked or failed to upgrade, and our SSL checker reports the certificate side of it.

Will the move cost us search traffic?

A short dip while both versions are known is normal and recovers. A lasting drop is a sign that something in step 5, 6 or 7 is incomplete — usually 302 redirects instead of 301, canonical tags still pointing at http://, or a sitemap that was never resubmitted.

Why pay for a certificate when free ones exist?

The encryption is identical. What you pay for is the validation level — a free certificate proves control of the domain and nothing about the company — plus a warranty, a site seal, support when an installation fails, and certificates that last longer than 90 days.

How do we avoid an expired certificate?

Automate the renewal if your platform supports ACME, and keep a calendar reminder as a backup. We notify you before expiry as well, but a notification only works if it reaches someone who still reads that mailbox.

Ready to move?

Pick the certificate that matches the names you listed in step 1, or ask us and we will match them for you.