What does Google say about SEO? /

Official statement

A new HTTPS report is now available in Search Console. It makes it easier to identify problems preventing a page from being served securely. HTTPS is part of the page experience ranking factor.
🎥 Source video

Extracted from a Google Search Central video

💬 EN 📅 28/09/2022 ✂ 14 statements
Watch on YouTube →
Other statements from this video 13
  1. Will structured data pros/cons in reviews really change the game in search results?
  2. Can structured product data really transform your Google visibility?
  3. Is Google's new Merchant Listings report a game-changer for e-commerce SEO?
  4. Does the Helpful Content Update really penalize your entire site, or just problem pages?
  5. Should you really forget technical SEO to please Google with 'people-first' content?
  6. Why did Google roll out the Helpful Content Update exclusively in English at first?
  7. Why does Google finally maintain a dedicated page to track ranking algorithm updates?
  8. How can you unlock your videos with Google's new Video Indexing Report in Search Console?
  9. How can you leverage the new video data in Google's URL Inspection Tool to boost your rankings?
  10. Is Google's Search Console classification update changing how you should prioritize your SEO tasks?
  11. Is Google really abandoning geotargeting controls in Search Console?
  12. Does Google really enforce a strict 15 MB HTML crawl limit per page?
  13. How can you optimize your feeds to make the most of Google Discover's Follow feature?
📅
Official statement from (3 years ago)
TL;DR

Google has launched a dedicated HTTPS report in Search Console to identify security issues preventing your pages from being served over HTTPS. This report aims to simplify the detection of technical errors related to SSL certificates, mixed content, or redirects. HTTPS remains a ranking signal within the page experience factor.

What you need to understand

Why is Google rolling out a dedicated HTTPS report now?

HTTPS has been a confirmed ranking signal since 2014, but its technical implementation remains error-prone. Expired certificates, mixed content (HTTP/HTTPS on the same page), or misconfigured redirects can prevent Google from serving a secure version.

This new report centralizes these issues in Search Console. Previously, you had to cross-reference multiple tools (SSL certificate, Chrome DevTools, server logs) to identify the source of an HTTPS problem. Google is simplifying the diagnosis.

What exactly is the page experience factor?

The page experience factor groups several signals together: Core Web Vitals, absence of intrusive pop-ups, optimized mobile navigation, and HTTPS. It's not an isolated factor but a set of criteria that weigh into rankings, especially when relevant content is tied.

HTTPS is the most binary component: either the page is secure or it isn't. Core Web Vitals, on the other hand, accept nuances (good, fair, poor). This is why fixing HTTPS remains a priority — it's a technical quick win.

What problems can this report concretely detect?

The report identifies URLs served over HTTP when the site should be HTTPS, expired or invalid SSL certificates, and mixed content. The latter occurs when an HTTPS page loads resources (images, scripts, CSS) over HTTP.

  • Expired or misconfigured SSL certificates (incomplete certificate chain, domain not covered)
  • Mixed content (mixed content) blocking or passive detected by Google
  • Missing or poorly implemented HTTP→HTTPS redirects on certain URLs
  • Pages accessible in duplicate (HTTP and HTTPS) without clear canonicalization

SEO Expert opinion

Does this report really change the game for SEO professionals?

Let's be honest: for a site properly migrated to HTTPS, this report should remain empty. If you see critical errors, it means the initial migration was rushed or regressions have appeared (certificate not renewed, new template with mixed content).

The real value is continuous monitoring. A certificate expires, a CMS adds an HTTP resource, a misconfigured CDN serves mixed content — and you don't see it until Google tells you. This report becomes a safety net.

Does HTTPS really have a measurable impact on rankings?

Google has been saying for years that HTTPS is a "light signal". In practice, the direct impact on rankings remains marginal — except in cases of visible security alerts in SERPs ("not secure").

[To be verified] The indirect effect is more tangible: an HTTP site displays a warning in Chrome, which can degrade organic CTR and increase bounce rate. Google measures these behavioral signals, even if the company never admits it explicitly.

What HTTPS errors still go unnoticed despite this report?

The report doesn't detect everything. HTTPS performance issues (slow SSL negotiation, obsolete TLS versions) are not covered. Same for self-signed certificates or certificate chain errors that don't technically prevent connection but degrade browser trust.

If your site uses a CDN or reverse proxy (Cloudflare, Fastly), some HTTPS errors may be hidden from Google's perspective but visible to end users. Always test under real conditions.

Practical impact and recommendations

What should you prioritize checking in this report?

Log into Search Console and access the new HTTPS report. Identify the flagged URLs and categorize them by error type: certificate, mixed content, redirects. Start with expired certificates — that's the most blocking issue.

For mixed content, use Chrome DevTools (Console tab) on the affected pages. Look for HTTP resources and replace them with HTTPS equivalents. Also check your CMS templates — a single misconfigured widget can infect hundreds of pages.

How do you prevent HTTPS regressions after migration?

Set up automated monitoring of your SSL certificate (expiration, validity). Tools like SSL Labs or Qualys can send alerts before expiration. Also configure a CSP (Content Security Policy) to block mixed content before it reaches the browser.

Force HTTPS at the server level with HSTS (HTTP Strict Transport Security). This ensures that even if an HTTP URL is crawled, the browser (and Google) will automatically convert it to HTTPS.

What checklist should you apply for a perfectly secure HTTPS site?

  • Valid SSL certificate covering all subdomains and auto-renewed
  • HTTP→HTTPS 301 redirects on all URLs, including www/non-www
  • HTTPS canonicals on all pages (verify canonical tags in HTML)
  • XML sitemap in HTTPS submitted to Search Console, without HTTP URLs
  • Mixed content eliminated: images, CSS, JS, iframes, all HTTPS
  • HSTS enabled with sufficient duration (e.g., max-age=31536000)
  • SSL certificate monitoring with alerts 30 days before expiration
This HTTPS report doesn't replace a full technical audit, but it flags critical errors that often go unseen. Fix them quickly to avoid traffic loss or silent de-ranking. If managing your HTTPS infrastructure (CDN, proxy, multi-domain) becomes too complex to handle alone, partnering with a specialized SEO agency can save you valuable time and prevent costly production errors.

❓ Frequently Asked Questions

Le passage en HTTPS améliore-t-il directement mon positionnement Google ?
HTTPS est un signal de ranking confirmé mais considéré comme « léger » par Google. Son impact direct est marginal, mais il évite les avertissements de sécurité dans Chrome qui dégradent le CTR et la confiance utilisateur.
Que faire si mon certificat SSL est valide mais que Google signale des erreurs HTTPS ?
Vérifiez les contenus mixtes (ressources HTTP sur pages HTTPS) et la chaîne de certificat complète. Certains CDN ou proxies peuvent masquer des problèmes côté Google. Testez avec SSL Labs et Chrome DevTools.
Faut-il soumettre à nouveau mon sitemap après correction des erreurs HTTPS ?
Oui, soumettez un sitemap HTTPS propre sans URLs HTTP. Utilisez aussi l'outil Inspection d'URL dans Search Console pour forcer la réindexation des pages corrigées.
Les certificats Let's Encrypt gratuits sont-ils suffisants pour le SEO ?
Oui, Google ne fait aucune distinction entre certificats payants et gratuits tant qu'ils sont valides et correctement configurés. Let's Encrypt est largement accepté.
Un site partiellement en HTTPS (seulement certaines pages) est-il pénalisé ?
Google traite chaque URL individuellement, mais un site mixte crée confusion et contenus dupliqués. Mieux vaut migrer l'intégralité du site en HTTPS pour éviter les problèmes de canonicalisation.
🏷 Related Topics
Domain Age & History HTTPS & Security AI & SEO Search Console

🎥 From the same video 13

Other SEO insights extracted from this same Google Search Central video · published on 28/09/2022

🎥 Watch the full video on YouTube →

Related statements

💬 Comments (0)

Be the first to comment.

2000 characters remaining
🔔

Get real-time analysis of the latest Google SEO declarations

Be the first to know every time a new official Google statement drops — with full expert analysis.

No spam. Unsubscribe in one click.