HTTPS encrypts traffic between visitors and your website. Browsers label HTTP sites as “Not secure”, and HTTPS is expected for any modern website.
Steps
- Install an SSL certificate; many hosts offer free certificates.
- Set your CMS site URL to https.
- Redirect all HTTP URLs to HTTPS with 301 redirects; create rules with our redirect generator.
- Fix mixed content: images, scripts and stylesheets still loaded over HTTP.
- Update internal links, canonical tags and sitemaps to HTTPS.
- Add the HTTPS property in Search Console.
Finding mixed content
Browser developer tools show warnings. Search your database or code for “http://” links; check URLs with our URL parser.
Do not forget
- Update links in Google Business Profile, social profiles and ads.
- Check forms and payment integrations.
Keep certificates renewed
Free certificates renew automatically on most hosts; check that it is working.
Read SSL certificate types.
Want the full picture? This article is part of Business websites: the complete guide, our in-depth guide with everything in one place.


