Website shows “Not secure”
Your site runs on an insecure connection. Browsers show visitors “Not secure” before they read a word.
How to see it yourself, in a minute
- Type your address into Chrome without “https://” in front.
- Look at the left of the address bar. If it says “Not secure” or shows an open padlock with a line through it, this is you.
- Now type it with “https://”. If the page fails or shows a warning, there is no certificate at all.
Or paste your address into the free audit, which checks this and seventeen other faults in ten seconds.
Why it matters
Every modern browser marks a plain-HTTP site as “Not secure” in the address bar, and Google has ranked secure sites ahead of insecure ones since 2014. Visitors who see the warning leave, and any form on the page sends what they type in the clear.
Google has ranked secure sites above insecure ones since 2014 and marks the insecure ones in the results themselves. On a business site with a form, the practical effect is that a share of visitors, often a third on a phone, close the tab at the warning. If your site brings you ten enquiries a month, this fault is probably costing three of them.
How we fix it
We install a proper certificate, redirect every old address to the secure one, fix the links and images that still point at the old version, and tell Google which copy is the master.
- Issue a certificate (free, from Let's Encrypt) and set it to renew itself, with a check that emails us three weeks before it could lapse.
- Redirect every old http address to its https twin so no link, bookmark or Google result breaks.
- Fix the images, scripts and styles still loading over http so the padlock actually shows.
- Update the canonical tags and sitemap and resubmit in Search Console so Google indexes the secure copy.
How long: Usually a half day.
Questions people ask about this
- Will my Google rankings drop when the address changes?
- Not if the redirects are done properly. Every page redirects to its exact secure twin, Google follows them within days, and the ranking signals move with them. Done badly, with everything redirecting to the homepage, they do drop.
- Is the certificate an ongoing cost?
- No. Let's Encrypt certificates are free and renew automatically. The only cost is making sure the renewal actually runs, which is what the monitoring is for.
- My hosting company says they will do it for €150 a year.
- That is a paid certificate you do not need. Ask them to enable the free one; if they will not, that tells you something about the hosting.
People usually find this page by searching
- “website says not secure”
- “how to fix not secure website”
- “http to https”
Has your site got it?
Paste your address. This and seventeen other faults, checked in seconds.
Free, on screen in about ten seconds, no call. We fetch your homepage once, the way a visitor's browser does, and nothing else.
Or fix the lot at once
If the audit finds five or more, a rebuild is usually cheaper than five fixes. Prices are on the page.