What is HTTPS migration?
HTTPS is the safe, locked version of a web address. HTTP is the old, unlocked version. An SSL certificate is the digital badge that turns the lock on. To migrate means to move your site fully to HTTPS. SEO means helping search engines such as Google find and rank your site. To search engines, the HTTP and HTTPS versions look like two different sites. So you must tell them about the move.
Before you start
Take a full backup of your files and database. Choose a quiet time, because small errors can show up during the move.
Checklist
- Get an SSL certificate. Install one for your domain, including the www version. Ask Hostvento support if you need help.
- Test the certificate. Open your site with
https://and check that the padlock shows. - Update your internal links. Change links, images, scripts and style files from
http://tohttps://. In WordPress, update the addresses in Settings, then General, and use a search and replace plugin for old links. - Fix mixed content. This is when a safe page loads some items over HTTP. Use the browser Console to find them.
- Add 301 redirects. A 301 redirect tells browsers and search engines that a page has moved for good. Add this to your
.htaccessfile on Apache:
This sends every HTTP visit to the HTTPS version. Back up the file first.RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] - Update canonical tags. A canonical tag tells search engines which version of a page is the main one. Make it use
https://. - Update your sitemap. The sitemap is a list of your pages for search engines. Make it list HTTPS addresses.
- Update robots.txt. Check that it does not block your site and that it points to the new sitemap.
- Add the HTTPS site to Google Search Console. Add it as a new property, then send your new sitemap.
- Update other places. Change your links in Google Analytics, social profiles, email signatures, ads and other sites you control.
- Check third-party tools. Make sure widgets, forms, and payment pages work over HTTPS.
- Watch your traffic. Check Search Console for errors for a few weeks. Some small ups and downs are normal.
Tip: Keep your certificate valid. If it expires, visitors see a scary warning page.
Quick recap
- Install a certificate and test HTTPS.
- Fix all internal links and mixed content.
- Use 301 redirects from HTTP to HTTPS.
- Update canonical tags, sitemap and Search Console.
- Watch your traffic after the move.