SEO Guidelines to Consider When Migrating from HTTP to HTTPS Date: March 30, 2017 By: Aumcore
Page 1 of 8
What is HTTPS? HTTPS (Hypertext Transfer Protocol Secure) is an internet communication protocol that protects the integrity and confidentiality of your users' data between the user's computer and the site. For example, when a user enters data into a form on your site to subscribe to updates or purchase a product, HTTPS protects that user's personal information between the user and the site. Users expect a secure online experience when providing data via a website. This is the standard for all communication on the web.
Business Benefits of Migrating From HTTP to HTTPS •
Security: HTTPS makes the website secure from hacking and other security breaches. This is one of the biggest reasons to migrate from HTTP to HTTPS.
•
SEO: HTTPS helps SEO by improving the website ranking in search engine results. As per the update published on 6th August, 2014 on Google’s official blog: (https://webmasters.googleblog.com/2014/08/https-as-ranking-signal.html), security is the top priority for Google, and Google promotes HTTPS because it helps online business stay secure.
•
Brand Trust: HTTPS builds trust with visitors. As per the company Globalsign survey,”77% of websites visitors are concerned about their data being intercepted or misused online.” It is important to let your visitors know you are secure and that their information will be protected. It helps to increase trust and sales.
•
Accurate Referral Traffic Data: If you are using Google Analytics to track website traffic and other performance, it is mandatory to migrate HTTP to HTTPS, because in Google analytics, HTTPS to HTTP referral data is blocked. Traffic from a HTTPS website to a HTTP website will not be visible under the referral traffic of the HTTP website, and all traffic from HTTPS websites are considered as direct traffic. This is because HTTPS is not compatible with HTTP websites.
Page 2 of 8
As per BuiltWith (A Technology Look-up website), “Business” websites are the highest on
HTTPS Website Trends
As per BuiltWith, approximately 10.1% of top 1M websites (Home Pages) are using HTTPS to secure their data and to build user trust. The graph below illustrates this fact: HTTPS protocol, followed by “shopping” websites in the second position. As we can see in the above graph, most of the business websites have migrated from HTTP to HTTPS protocol and are currently receiving the benefits of HTTPS.
SEO Guidelines to Migrate HTTP URLs to HTTPS URLs Page 3 of 8
Below are SEO guidelines for before and after migration when migrating website pages from HTTP to HTTPS. These guidelines will help a business website avoid any SEO loss if implemented correctly.
Before Migration from HTTP to HTTPS 1. Prepare a List of Website Pages: Make a list of website pages so that you have all the URLs in one location that can easily be compared once you have implemented the HTTPS. For the HEOS NL case, we have a list of all the HEOS NL microsite pages. 2. Crawl Website Pages: Before migrating, crawl websites pages through the Google search console. To see the comparisons and benefits of SEO benefits, keep the record of the search engine crawling status (page caching date) and position of the pages in the search engine that are going to be migrated. This will be helpful to illustrate the difference after implementation of the HTTPS protocol. For HEOS NL, all the pages of the HEOS NL microsite are in Google index.
3. Website Traffic Status: Before migrating, keep a traffic report of the website to see the difference before and after migration of the website. For HEOS NL, we have monthly traffic status record.
4. External & Internal Backlinks: Keep records of internal and external links to and from the website to receive the benefits of old back links. This can be easily extracted from the Google search console tool, which is free and provided by Google to know the health of the website. Having a record of internal site linking helps to make appropriate changes once HTTPS is implemented on the website. 5. Check Robots.txt: Keep the status of the robots.txt file, whether page URLs are blocked or not. 6. Page Speed: Check the page speed and keep a record of page download time for all individual pages on both mobile and desktop. This will help to provide the status of migration impact on the page download time. We will record the Google page speed score and page download time for key pages. Technical Guidelines 1. SSL certificate works best: There are 3 types of HTTPS SSL certificates, and among these three, anyone can be used to make a website HTTPS compatible. Page 4 of 8
a. Extended Validation (EV) SSL Certificates b. Organization Validation (OV) SSL Certificates c. Domain Validation (DV) SSL Certificates Business can select a type of SSL certificate as per their security concerns and budget allocation. 2. HTTPS Certificate Types: Decide the kind of certificate you need: single, multidomain, or wildcard certificate and get an updated certificate from a reliable CA that offers technical support. a. Single Certificate: Single certificates are for single secure origin (e.g. www.aumcore.com). b. Multi-domain certificate: Multi-domain certificates are for multiple wellknown secure origins (e.g. www.aumcore.com, cdn.aumcore.com, aumcore.co.uk). c. Wildcard Certificate: Wildcard certificates are for a secure origin with many dynamic subdomains (e.g. a.aumcore.com, b.aumcore.com). 3. It is recommended to use a 2048-bit key certificate because, it is highly secure and is recommended by Google. 4. Use relative URLs for resources that reside on the same domain that’s secured. 5. Configure HTTPS for the server. Follow these instructions provided by Mozilla to implement the SSL certificates. After Migration from HTTP to HTTPS SEO Checklist to Maintain Current Rankings & Traffic: Post implementation of HTTPS protocol, follow the below checklist to ensure that implementation is correct. 1. Page Elements (CSS, JS Images & widgets): Make sure every element of your website uses HTTPS including widgets, java script, CSS files, images and your content delivery network. 2. Place 301 Redirection: Use 301 redirects to point all HTTP URLs to HTTPS. This is a nobrainer to most SEOs. Do not use 302 & 303 redirections. Make sure the content on your HTTP site and your 3. Content on HTTP and HTTPS: HTTPS are the same to avoid duplicate content issues.
Page 5 of 8
4. Canonical Tags: Make sure all canonical tags point to the HTTPS versions of the URLs. 5. Page Internal Links: Rewrite hard-coded internal links (as many as is possible) to point to the HTTPS URLs. This is better than pointing to the HTTP versions and relying on 301 redirects. 6. Search Engine Webmaster Tools: Register the HTTPS URL versions in both Google search console and Bing Webmaster Tools. 7. Google Search Console: Use the Fetch and Render function in Google search console tool to ensure Google can properly crawl and render your site. 8. XML Sitemap: Update your sitemaps to reflect the new URLs. Submit the new sitemaps to Webmaster Tools. Leave your old (HTTP) sitemaps in place for 30 days so search engines can crawl and "process" your 301 redirects. 9. Robots.txt: Update your robots.txt files. Add your new sitemaps to the file. Make sure your robots.txt doesn't block any important pages. 10. Google Analytics Code: If necessary, update your analytics tracking code. This is required to change when you are using the old version of Google Analytics. Change name of your website default URL to HTTPS.
11. HTTP Strict Transport Security (HSTS): Implement HTTP Strict Transport Security (HSTS). This response header tells user agents to only access HTTPS pages even when directed to an HTTP page. This eliminates redirects, speeds up response time, and provides extra security. 12. Disavow file: If you have a disavow file, be sure to transfer over any disavowed URLs into a duplicate file in your new Webmaster Tools profile.
Check the Status of HTTPS URL Setup and Implementation:
Page 6 of 8
1. Use tools like SSL Check (https://www.ssllabs.com/ssltest/) to scan your site for nonsecure content. Report grade should be “A” if the HTTPS page URLs are working properly. 2. Check HTTPS redirects and legacy redirects to ensure they work correctly. 3. Monitor the “Crawl Errors” report in the Search Console and address errors as appropriate.
Off-Site Changes Post the migration of HTTP URLs to HTTPS make sure you have made the changes of page URLs on external digital and print media. 1. Social Platforms: In all the owned social media platforms, remove linking of OLD HTTP page URLS and replace with the HTTPS based page URLs. The same applies for your regular social media postings so that people will know about your HTTPS based URLs and directly land on the new URLs (no 301 redirection is required). Only include HTTPS based URLs when the social media management team plans the social media content calendar.
2. External Footprints (Backlinks): Make a list of all external footprints (extracted from GWT) and send a request to replace the old HTTP page URLs to HTTPS page URLs. This will help in receiving link benefit to your actual site pages. Though we are redirecting them, it is better to replace them with HTTPS based URLs wherever possible.
3. Print Media: Remove all the old HTTP URLs from print media, email signatures, visiting cards, Billboard banners etc., and only use the HTTPS page URLs to promote websites.
4. Email & Other Paid Campaigns: Remove all the old URLs from email campaigns and other paid marketing campaigns to stop further promotion of old page URLs wherever possible.
Page 7 of 8
Thank You Connect with us on Social Media
Vimeo
Blog
215 Park Ave S. Suite 1802 New York, NY 10003 (212) 776-1414
Page 8 of 8
Contact