SSL and HTTPS: a Website Setup Checklist
A practical checklist for enabling HTTPS, checking redirects and avoiding common mixed-content problems.
Before installing a certificate
Confirm the exact hostnames the certificate must cover, such as the root domain and the www version. Check who controls DNS and the web server, and arrange a maintenance window if the site is business-critical. Use the certificate provider’s instructions for validation and installation.
Enable HTTPS and redirect carefully
After installing the certificate and confirming it works, configure the site to use HTTPS consistently. Add an appropriate HTTP-to-HTTPS redirect and update canonical URLs, sitemaps, internal links and any application settings that still refer to HTTP.
Check for mixed content
A page can load over HTTPS while still requesting images, scripts or stylesheets over HTTP. Inspect important pages and browser developer tools, update resource URLs and re-test forms, payment flows and embedded content.
Monitor expiry and renewals
Record certificate ownership, renewal method and expiry notices. Test renewal processes before a certificate expires, particularly when DNS validation or manual server steps are required. HTTPS is a configuration to maintain, not a one-time checkbox.
Frequently asked questions
Does an SSL certificate automatically move all pages to HTTPS?
No. The certificate enables encrypted connections, but you must also configure the site and redirects to use HTTPS and update resources that still load over HTTP.
What is mixed content?
Mixed content occurs when an HTTPS page loads some resources over an insecure HTTP connection. Update those resource URLs to HTTPS or remove resources that cannot be served securely.