Agent Websites

    Real Estate Website Security: What HTTPS Actually Protects

    Saige Team·October 16, 2026·10 min read
    Real Estate Website Security: What HTTPS Actually Protects

    An agent asked recently whether their website needed an SSL certificate, since it does not process payments. It already had one, bundled free with hosting the way almost every provider does it now. The better question was not whether to buy HTTPS. It was whether the one already installed was actually working.

    What HTTPS actually does

    HTTPS encrypts the connection between a visitor's browser and your server. Without it, a lead form asking for a name, phone number, or email address sends that information as plain text, readable by anything sitting between the visitor and the site: a shared office network, a coffee shop router, an internet provider.

    The "S" stands for secure, and the padlock icon in the address bar is the visible summary of a certificate issued by a certificate authority, confirming the connection is encrypted and the site is who it claims to be. It is a statement about the pipe the data travels through, separate from the content of the page or the trustworthiness of the business running it.

    For a real estate agent, the page most exposed to this is the lead form, not a payment page, because most agent sites do not process payments at all. The form asking a buyer to leave their phone number is the page where HTTPS matters most.

    Why Chrome specifically calls this out

    Chrome has marked pages with unencrypted password fields as "Not Secure" since 2017, and the browser's own developer documentation confirms the trigger: any page with a password or payment input served over plain HTTP gets flagged, and the warning shows in the address bar itself, not buried in a settings menu.

    A real estate lead form usually asks for a phone number rather than a password, so it does not automatically trigger that specific warning. But the underlying exposure is the same, and browsers have been moving toward flagging all HTTP pages more broadly over time. A visitor who has learned to distrust the "Not Secure" label from other sites brings that same instinct to yours, whether or not the exact warning fires on your form.

    The practical effect is a form that does not get filled out, for a reason the visitor may not consciously name. They see something that looks off, and they leave instead of typing a phone number into it.

    Does HTTPS actually affect rankings

    A small amount. Google confirmed HTTPS as a ranking signal in a 2014 announcement, and was specific about the size: a lightweight signal, affecting fewer than 1% of global queries at the time, carrying less weight than signals like content quality.

    That framing has not been walked back publicly since. HTTPS functions as closer to a baseline expectation than a competitive lever. A site missing it is not automatically buried, but a site with it gets no meaningful boost either, all else being equal. The pages that actually rank are still the ones answering the buyer's question clearly, not the ones with the newest certificate.

    Where HTTPS earns its keep is less about the ranking algorithm and more about the visitor's decision to stay on the page at all, which is the harder problem for most agent sites anyway.

    How to check your own site in two minutes

    Open your homepage in an incognito or private browser window, which avoids any cached login state masking a problem. Look at the address bar.

    A padlock icon, or simply no warning next to the address, means the certificate is present and valid. A "Not Secure" label, or the browser silently redirecting your typed https:// address back down to http://, means something is missing or misconfigured. Click through to a page with your contact form specifically and repeat the check, since it is possible for a homepage to be secure while a subpage generated by an older plugin or template is not.

    Google's Search Console also has a dedicated HTTPS report that shows what share of the pages Google has crawled on your site are served securely. A site fully on HTTPS shows close to 100%. Anything meaningfully below that points to specific pages worth checking individually rather than a wholesale problem.

    The two ways a working setup quietly breaks

    The first is a hosting or domain change. Some hosts reissue a certificate automatically when a site moves, and some do not, so a site that showed the padlock cleanly on the old host can start showing a warning on the new one with zero changes to the site's actual content. This is the same category of risk covered in choosing a domain name: a migration that moves the address without carrying the redirect and certificate setup along with it loses ground on both fronts at once.

    The second is mixed content. An HTTPS page can still load an individual image, script, or embedded video over plain HTTP, usually because the code referencing that resource was written before the site moved to HTTPS and was never updated. Browsers treat that as partially secure and show a warning triangle instead of a clean padlock, even though the page itself is technically on HTTPS. It traces back to one stale URL more often than to a deeper problem, but it needs to be found and fixed resource by resource.

    Neither failure mode announces itself. A visitor does not email an agent to report a certificate warning. They close the tab.

    What a free certificate actually covers

    Nearly every modern hosting plan bundles a free certificate from Let's Encrypt, a nonprofit certificate authority, and it is functionally identical encryption to a certificate someone pays for separately. Browsers trust it the same way.

    The one operational detail worth knowing: Let's Encrypt certificates are valid for 90 days, and the organization recommends renewing at the 60-day mark to leave a buffer. Almost every host automates that renewal now, which is why most agents never think about it. It becomes visible only when the automation fails, usually after a hosting change or a lapsed billing detail, and the certificate quietly expires without anyone noticing until a visitor sees the warning.

    There is no tier of "better" HTTPS to buy for a real estate site. A free, correctly renewed certificate does the entire job.

    Where this fits next to the rest of the site

    HTTPS is a floor, not a differentiator. It stops one specific failure, a lead form or connection visibly flagged as unsafe, and it does that job completely once it is set up correctly. It does not make a generic template feel trustworthy, and it will not fix a form abandoned for unrelated reasons like too many required fields or no confirmation after submitting.

    The sites that convert well tend to have HTTPS working correctly as one item on a longer list: real photography, a phone number that gets answered, testimonials that read as specific rather than generic, and a form short enough to finish on a phone. HTTPS earns its place by being invisible when it works and glaring when it does not, which is exactly why it is worth the two-minute check even on a site nobody has touched in years.

    The takeaway

    HTTPS protects the data in a lead form, contributes a small amount to how a page ranks, and is bundled free with almost every hosting plan available today. The failure mode worth watching for is not the absence of a certificate on a new site, which is rare now, but a working setup quietly breaking after a hosting change, a domain move, or one stale resource still loading over HTTP.

    Check it the same way a visitor would: open the site in a private window and look at the address bar. If anything about it looks off, that is worth fixing this week, independent of any larger redesign plan. If you are already weighing a bigger rebuild, HTTPS is one detail among several worth getting right the first time. Read more about what buyers actually check when they land on an agent's site or see how a rebuild handles the technical basics before deciding whether a fix or a rebuild is the right scope. Questions about a specific setup are welcome through the contact page or the FAQ.

    Plot shares general guidance for real estate agents and brokers. It is not individualized business, financial, or legal advice for your specific situation.

    Frequently asked questions

    My site does not process payments. Do I still need HTTPS?

    Yes, because the field that matters is not a credit card field, it is your lead form. Any page asking for a name, email, or phone number sends that data in the clear over a plain HTTP connection, which is exactly the pattern Chrome has flagged with a warning since 2017. Payment processing is one reason for HTTPS, not the main one for an agent site.

    How do I check whether my own site actually has HTTPS working right now?

    Open your homepage in an incognito or private browser window and look at the address bar. A padlock icon or a plain address with no warning means it is working. A 'Not Secure' label, or the browser silently rewriting the address from https to http, means the certificate is missing, expired, or misconfigured, and it is worth checking today rather than waiting for a redesign.

    I switched hosting providers last year. Could that have broken my HTTPS setup silently?

    It can, and this is one of the more common ways a working site quietly breaks. Some hosts issue a new certificate automatically on migration and some do not, so a site that showed the padlock on the old host can start showing a warning on the new one without any change to the site's content. Check the address bar after any hosting or domain change, not just after a redesign.

    Is a free certificate from my hosting provider as good as a paid one for a real estate site?

    For an agent site, yes. Free certificates from Let's Encrypt are functionally identical encryption to a paid certificate and are trusted by every major browser the same way. Let's Encrypt certificates are valid for 90 days and the organization recommends renewing at the 60-day mark, which almost every host now automates, so most agents never see the renewal happen.

    Does HTTPS actually affect where my site ranks in Google?

    A small amount, and Google has been clear about how small since it confirmed HTTPS as a ranking signal in 2014: a lightweight signal affecting under 1% of queries at the time, weighing less than content quality. Treat it as a baseline a site needs to have in place, not as a lever that moves rankings on its own.

    What is 'mixed content' and why does my padlock sometimes show a warning triangle instead?

    Mixed content is when an HTTPS page still loads some resources, usually an image, a script, or an embedded video, over plain HTTP. Browsers treat that as only partially secure and show a warning icon instead of a clean padlock, even though the page itself is on HTTPS. It usually traces back to an old image URL or embed code that was never updated after a migration to HTTPS.

    If a redesign moves my site to a new address, does my HTTPS setup carry over automatically?

    No, it needs to be set up again on the new address, and the redirect from the old address to the new one needs to point to the HTTPS version specifically, not back to HTTP. This is closely related to the domain question covered in [choosing a real estate website domain name](/plot/real-estate-website-domain-name): a move that skips the redirect step loses both the old address's history and, if HTTPS is missing on arrival, the trust signal on the new one.

    Can a visitor's antivirus or office network block my site if HTTPS is missing?

    It happens more than agents expect. Some corporate networks and antivirus tools flag or block unencrypted form submissions by policy, which means a buyer trying to reach you from a work computer can be stopped before your form ever loads, with no error message that points back to the actual cause.

    How does Search Console's HTTPS report help me monitor this over time?

    Google added an HTTPS report to Search Console that tracks what share of your site's crawled pages are served securely, so a partial break, like a subfolder still on HTTP after a migration, shows up as a percentage rather than staying invisible until a visitor complains. It is one more panel worth checking during a regular site audit.

    Does a Saige rebuild handle HTTPS setup automatically?

    A Saige rebuild is built on modern hosting where HTTPS is on by default and renews on its own, so it is not something an agent needs to configure or remember to renew. The [free rebuild preview](/services/website-rebuild) shows what the rebuilt site looks like before anything on the live site changes.

    My browser shows 'Secure' but a client still says the site looks untrustworthy. What else is going on?

    HTTPS covers the connection, not how the page reads. If the padlock is present but the site still feels untrustworthy, the cause is usually elsewhere on the page: stock photography that looks generic, no real testimonials, or a missing contact page, which are covered in [what buyers actually check on an agent website](/plot/what-buyers-check-on-agent-websites) and [testimonials that actually convince](/plot/real-estate-testimonials-that-convince).

    #website security#HTTPS#agent websites#SEO#lead forms

    Free guide for agents

    Find out why Google and ChatGPT skip your website

    The Real Estate Ranking Guide walks through what both of them read, what they ignore, and a 90-day plan you can start this month. Free, and it opens as soon as you submit.

    Call 604.401.4849