Technical SEO

HTTPS and HSTS

Encrypted transport for web traffic (HTTPS) and a header (HSTS) that forces browsers to use it. HTTPS is a baseline ranking and trust signal.

By Shimon Carroll, Founder, SEO for AI Agents · Last updated

HTTPS is HTTP over TLS: it encrypts the traffic between the browser and the server so it cannot be read or tampered with in transit. Google confirmed HTTPS as a lightweight ranking signal in 2014, and since then it has become a baseline expectation, browsers mark non-HTTPS pages as not secure, and many modern web features only work over HTTPS. For SEO it is table stakes: serve everything over HTTPS, redirect http to https, and avoid mixed content where a secure page loads insecure assets.

HSTS, HTTP Strict Transport Security, is a response header that tells browsers to only ever connect to the site over HTTPS, even if a user types http or follows an old link. This closes the small window where an initial insecure request could be intercepted and redirected. With the preload directive, a domain can be added to a list browsers ship, so the first connection is secure too.

The related hygiene items are a valid, non-expired certificate, a clean redirect chain (one hop from http to the canonical https URL, not a chain), no mixed content, and modern TLS configuration. These do not move rankings much on their own, but their absence undermines trust and can break rendering. We check certificate validity, redirect chains, mixed content, and HSTS presence.

Primary sources