An agent asked recently whether their website needed an SSL certificate, since it does not process payments. It already had one, bundled free with hosting the way almost every provider does it now. The better question was not whether to buy HTTPS. It was whether the one already installed was actually working.
What HTTPS actually does
HTTPS encrypts the connection between a visitor's browser and your server. Without it, a lead form asking for a name, phone number, or email address sends that information as plain text, readable by anything sitting between the visitor and the site: a shared office network, a coffee shop router, an internet provider.
The "S" stands for secure, and the padlock icon in the address bar is the visible summary of a certificate issued by a certificate authority, confirming the connection is encrypted and the site is who it claims to be. It is a statement about the pipe the data travels through, separate from the content of the page or the trustworthiness of the business running it.
For a real estate agent, the page most exposed to this is the lead form, not a payment page, because most agent sites do not process payments at all. The form asking a buyer to leave their phone number is the page where HTTPS matters most.
Why Chrome specifically calls this out
Chrome has marked pages with unencrypted password fields as "Not Secure" since 2017, and the browser's own developer documentation confirms the trigger: any page with a password or payment input served over plain HTTP gets flagged, and the warning shows in the address bar itself, not buried in a settings menu.
A real estate lead form usually asks for a phone number rather than a password, so it does not automatically trigger that specific warning. But the underlying exposure is the same, and browsers have been moving toward flagging all HTTP pages more broadly over time. A visitor who has learned to distrust the "Not Secure" label from other sites brings that same instinct to yours, whether or not the exact warning fires on your form.
The practical effect is a form that does not get filled out, for a reason the visitor may not consciously name. They see something that looks off, and they leave instead of typing a phone number into it.
Does HTTPS actually affect rankings
A small amount. Google confirmed HTTPS as a ranking signal in a 2014 announcement, and was specific about the size: a lightweight signal, affecting fewer than 1% of global queries at the time, carrying less weight than signals like content quality.
That framing has not been walked back publicly since. HTTPS functions as closer to a baseline expectation than a competitive lever. A site missing it is not automatically buried, but a site with it gets no meaningful boost either, all else being equal. The pages that actually rank are still the ones answering the buyer's question clearly, not the ones with the newest certificate.
Where HTTPS earns its keep is less about the ranking algorithm and more about the visitor's decision to stay on the page at all, which is the harder problem for most agent sites anyway.
How to check your own site in two minutes
Open your homepage in an incognito or private browser window, which avoids any cached login state masking a problem. Look at the address bar.
A padlock icon, or simply no warning next to the address, means the certificate is present and valid. A "Not Secure" label, or the browser silently redirecting your typed https:// address back down to http://, means something is missing or misconfigured. Click through to a page with your contact form specifically and repeat the check, since it is possible for a homepage to be secure while a subpage generated by an older plugin or template is not.
Google's Search Console also has a dedicated HTTPS report that shows what share of the pages Google has crawled on your site are served securely. A site fully on HTTPS shows close to 100%. Anything meaningfully below that points to specific pages worth checking individually rather than a wholesale problem.
The two ways a working setup quietly breaks
The first is a hosting or domain change. Some hosts reissue a certificate automatically when a site moves, and some do not, so a site that showed the padlock cleanly on the old host can start showing a warning on the new one with zero changes to the site's actual content. This is the same category of risk covered in choosing a domain name: a migration that moves the address without carrying the redirect and certificate setup along with it loses ground on both fronts at once.
The second is mixed content. An HTTPS page can still load an individual image, script, or embedded video over plain HTTP, usually because the code referencing that resource was written before the site moved to HTTPS and was never updated. Browsers treat that as partially secure and show a warning triangle instead of a clean padlock, even though the page itself is technically on HTTPS. It traces back to one stale URL more often than to a deeper problem, but it needs to be found and fixed resource by resource.
Neither failure mode announces itself. A visitor does not email an agent to report a certificate warning. They close the tab.
What a free certificate actually covers
Nearly every modern hosting plan bundles a free certificate from Let's Encrypt, a nonprofit certificate authority, and it is functionally identical encryption to a certificate someone pays for separately. Browsers trust it the same way.
The one operational detail worth knowing: Let's Encrypt certificates are valid for 90 days, and the organization recommends renewing at the 60-day mark to leave a buffer. Almost every host automates that renewal now, which is why most agents never think about it. It becomes visible only when the automation fails, usually after a hosting change or a lapsed billing detail, and the certificate quietly expires without anyone noticing until a visitor sees the warning.
There is no tier of "better" HTTPS to buy for a real estate site. A free, correctly renewed certificate does the entire job.
Where this fits next to the rest of the site
HTTPS is a floor, not a differentiator. It stops one specific failure, a lead form or connection visibly flagged as unsafe, and it does that job completely once it is set up correctly. It does not make a generic template feel trustworthy, and it will not fix a form abandoned for unrelated reasons like too many required fields or no confirmation after submitting.
The sites that convert well tend to have HTTPS working correctly as one item on a longer list: real photography, a phone number that gets answered, testimonials that read as specific rather than generic, and a form short enough to finish on a phone. HTTPS earns its place by being invisible when it works and glaring when it does not, which is exactly why it is worth the two-minute check even on a site nobody has touched in years.
The takeaway
HTTPS protects the data in a lead form, contributes a small amount to how a page ranks, and is bundled free with almost every hosting plan available today. The failure mode worth watching for is not the absence of a certificate on a new site, which is rare now, but a working setup quietly breaking after a hosting change, a domain move, or one stale resource still loading over HTTP.
Check it the same way a visitor would: open the site in a private window and look at the address bar. If anything about it looks off, that is worth fixing this week, independent of any larger redesign plan. If you are already weighing a bigger rebuild, HTTPS is one detail among several worth getting right the first time. Read more about what buyers actually check when they land on an agent's site or see how a rebuild handles the technical basics before deciding whether a fix or a rebuild is the right scope. Questions about a specific setup are welcome through the contact page or the FAQ.



