HTTPS and trust

A browser marks an http site as not secure. Google described HTTPS as a lightweight ranking signal, not a shortcut to page one. Without the lock, forms and phone numbers travel on an open connection.

One secure version

The site should open on https, and the http address should 301 to that same secure URL. Two open versions side by side are duplicates: Google may index both.

An expired certificate shows a warning and drops trust. Renewal is part of sound hosting, not a surprise after a customer sees a red screen.

The state of the connection
StateWhat the visitor seesWhat to do
Valid httpsA lockKeep it and redirect to it
Open httpA browser warning301 to https
Expired certificateA red warningRenew it with the host
Mixed contentA weak lock or a warningReplace http URLs inside the page