To enable HTTPS on your website you need to install an SSL certificate on your server or hosting account, then force a redirect from HTTP to HTTPS using a rule in .htaccess or your CMS settings. The entire process can be completed in under 15 minutes with a free Let's Encrypt certificate.
This guide covers each step clearly: from obtaining the certificate to confirming that no HTTP request slips through unredirected.
Why You Need HTTPS (and What Happens Without It)
HTTPS encrypts the communication between a visitor's browser and your server. Without it, data travels in plain text and can be intercepted.
The concrete consequences of skipping HTTPS include:
- "Not Secure" browser warning in Chrome, Firefox, and Safari — an immediate trust killer.
- SEO penalty — Google has used HTTPS as a ranking signal since 2014.
- Exposed form data and payment information — legal and reputational risk.
- Modern browser blocks on pages with HTTP forms or mixed content.
An SSL certificate is no longer optional — it's the baseline expectation from both users and search engines.
Types of SSL Certificates: Which One to Choose
Before enabling HTTPS, pick the certificate type that fits your situation:
| Type | Validation | Best for | Approximate cost |
|---|---|---|---|
| Let's Encrypt (DV) | Domain | Informational sites, blogs, small businesses | Free |
| DV (Domain Validation) | Domain | Small to mid-sized projects | $0–$70 USD/year |
| OV (Organization Validation) | Company | Online stores, corporate portals | $70–$200 USD/year |
| EV (Extended Validation) | Extended | Banking, high-volume e-commerce | $200–$600 USD/year |
For most small business websites, Let's Encrypt is the right answer: it's free, automatic, and trusted by every major browser.
How to Install an SSL Certificate in cPanel (Let's Encrypt)
Most hosting providers include Let's Encrypt directly in cPanel. Here's how to activate it:
- Log in to your cPanel.
- Go to the Security section and click "SSL/TLS" or "Let's Encrypt SSL" (some providers label it AutoSSL).
- Select the domain (and the
wwwsubdomain) for which you want the certificate. - Click "Install" or "Run AutoSSL". The process takes 1–2 minutes.
- When finished, open
https://yourdomain.comin a browser and confirm the padlock appears.
If your hosting doesn't use cPanel, look for a "SSL", "Certificates", or "Security" section in your control panel — most providers offer an equivalent one-click button.
Manual Installation via CLI (Certbot)
If you have SSH access to a VPS or dedicated server, install the certificate with Certbot:
sudo certbot --apache -d yourdomain.com -d www.yourdomain.com
Certbot configures Apache or Nginx automatically and schedules automatic renewal. The certificate expires every 90 days but renews itself.
How to Force HTTPS: Redirect All HTTP Traffic
Installing the certificate enables HTTPS but does not remove HTTP access. You need a permanent (301) redirect so visitors and Google's crawlers always use the secure version.
Option 1: .htaccess Rule (Apache)
Edit the .htaccess file in your site's root and add at the top:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
This rule catches every HTTP request and redirects it to its HTTPS equivalent with a 301 (permanent) status code.
Option 2: WordPress Settings
In Settings → General, change both URLs (WordPress Address and Site Address) to start with https://. Then add the .htaccess rule above, or use the Really Simple SSL plugin, which handles everything automatically.
Option 3: Nginx Server Block
server {
listen 80;
server_name yourdomain.com www.yourdomain.com;
return 301 https://$host$request_uri;
}
Verifying That HTTPS Is Working Correctly
After enabling HTTPS and the redirect, check these points:
- Padlock in the browser: must appear on every page, including internal pages.
- No mixed content: open the browser developer tools (F12 → Console) to catch images, scripts, or fonts still loading over HTTP. Update those URLs to HTTPS.
- SSL Labs tool (
ssllabs.com/ssltest): analyzes your certificate configuration and gives you a grade (A, B, or lower) with specific recommendations. - Redirect check: type
http://yourdomain.comin the browser and confirm it automatically switches tohttps://.
If you need help configuring SSL in a complex environment or on a server without a control panel, the team at elenlace.com provides specialist hosting technical support.
Common Mistakes When Enabling HTTPS
Here are the most frequent issues and how to fix them:
- Mixed content: resources still loading from HTTP URLs. In WordPress, use a search-and-replace plugin (such as Better Search Replace) to update all URLs in the database.
- Certificate issued for the wrong domain: the certificate covers
yourdomain.combut notwww.yourdomain.com, or vice versa. Always include both variants when installing. - Redirect loop: happens when the
.htaccessrule conflicts with server settings. Check thatRewriteEngine Onisn't duplicated and that no other redirect block conflicts. - Expired certificate: Let's Encrypt lasts 90 days. If auto-renewal fails, the site shows a security error. Confirm that AutoSSL or the Certbot cron job is active and scheduled.
Key Takeaways
- HTTPS is mandatory for SEO, user trust, and data security.
- Let's Encrypt provides free, automatic SSL certificates trusted by all major browsers.
- Installing the certificate activates HTTPS, but you must add a 301 redirect to eliminate HTTP access.
- After enabling HTTPS, check for mixed content so the padlock appears on every page.
- Use SSL Labs and the browser console to diagnose any remaining issues.
Is your site still showing "Not Secure"? Visit elenlace.com and a specialist will help you activate HTTPS, fix mixed content, and get everything working in one service.
FAQ
Does HTTPS slow down my website?
The impact is minimal and virtually unnoticeable on modern servers. In fact, HTTPS is a prerequisite for HTTP/2 and HTTP/3, protocols that actually speed up page load times compared to HTTP/1.1.
Does my Let's Encrypt certificate renew automatically?
Yes, as long as the renewal process is active. In cPanel with AutoSSL, renewal is fully automatic. With Certbot on your own server, the installer schedules a cron job that renews the certificate 30 days before it expires.
Do I need HTTPS if my site doesn't sell anything or have forms?
Yes. Google marks any site without HTTPS as "Not Secure," which reduces visitor trust and can hurt your search rankings, regardless of whether the site handles sensitive data.
Can I have HTTPS on a subdomain separately from the main domain?
Yes. You can issue a certificate specifically for blog.yourdomain.com or any subdomain. Wildcard certificates (*.yourdomain.com) cover all first-level subdomains under a single certificate, though they aren't available for free from every provider.
Find more guides on security and hosting configuration in our hosting glossary section.
Further reading
Other providers and guides worth comparing: