{"id":4649,"date":"2023-06-08T10:25:24","date_gmt":"2023-06-08T10:25:24","guid":{"rendered":"https:\/\/afreeurl.com\/?p=4649"},"modified":"2023-06-08T10:25:24","modified_gmt":"2023-06-08T10:25:24","slug":"google-responds-if-security-headers-offer-ranking-influence","status":"publish","type":"post","link":"https:\/\/afreeurl.com\/?p=4649","title":{"rendered":"Google responds if security headers offer ranking influence"},"content":{"rendered":"<p><\/p>\n<p>A recent Google SEO Office Hours included a question about whether a security header confers an influence on ranking.<\/p>\n<p>It&#8217;s not as far-fetched as it seems at first glance because a security header like the HSTS header plays an important role in ensuring a secure HTTPS connection, and HTTPS is a lightweight Google ranking signal.<\/p>\n<h2>HSTS security header<\/h2>\n<p>A header is a response that a server provides to a browser (or crawler).<\/p>\n<p>The most well-known header is the response header such as the 404 error response or the 301 response header.<\/p>\n<p>The purpose of an HTTP header is to provide additional metadata about the web page that a browser or crawler is requesting.<\/p>\n<p>Security headers are a special group of headers that apply different types of security to protect against various malicious attacks and keep the site safe for users.<\/p>\n<p>An HSTS security header is a response that tells the browser that the web page should only be accessed via HTTPS, never HTTP, and to request HTTPS next time.<\/p>\n<p>Using this header is better than just using a 301 redirect.<\/p>\n<p>When a browser accesses a site using HTTP and is redirected to HTTPS, the next time the browser requests a web page, it will request an HTTP page again, causing the server to do the redirect again.<\/p>\n<p>The important consideration is that the site that only uses a 301 redirect is still vulnerable to a man-in-the-middle attack.<\/p>\n<p>The HSTS header prevents this from happening by making the browser only request an HTTPS page, making the entire site more secure.<\/p>\n<p>Therefore, a site that uses an HSTS header is more secure with respect to HTTPS.<\/p>\n<h2>Does the HSTS header affect rankings?<\/h2>\n<p><strong>The question asked of John Mueller:<\/strong><\/p>\n<p>&#8220;Does the integration of security headers such as HSTS have an influence on classification?&#8221;<\/p>\n<p><strong>John Mueller replied:<\/strong><\/p>\n<p>&#8220;No, the HSTS header does not affect search.<\/p>\n<p>This header is used to tell users to go directly to the HTTPS version and is commonly used in conjunction with redirects to the HTTPS versions.<\/p>\n<p>Google uses a process called canonicalization to choose the most appropriate version of a page to crawl and index;  it is not based on headers like those used for HSTS.<\/p>\n<p>Using these headers is of course great for users.<\/p>\n<h2>HSTS is a good security practice<\/h2>\n<p>HSTS is a message to browsers, and according to John Mueller, Googlebot doesn&#8217;t rely on headers.<\/p>\n<p>However, good security practices are something any site should practice, regardless of whether they confer ranking influence or not.<\/p>\n<p>Chrome hosts an HSTS preload list that all browsers use to automatically use HTTPS, it&#8217;s hard-coded into the browser.<\/p>\n<p>Instructions on how to do this can be found at <a href=\"https:\/\/hstspreload.org\" target=\"_blank\" rel=\"noopener\">HSTS preload website<\/a>.<\/p>\n<p><strong>Listen to the Office Hours discussion at minute 4:57:<\/strong><\/p>\n<p class=\"vcont\"><iframe loading=\"lazy\" title=\"English Google SEO office-hours from June 2023\" width=\"760\" height=\"428\" src=\"https:\/\/www.youtube.com\/embed\/yZkmuLds8dw?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" allowfullscreen><\/iframe><\/p>\n<p>Featured image by Shutterstock\/ViDI Studio<\/p>\n<p>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/www.searchenginejournal.com\/security-headers-and-ranking-influence\/488781\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recent Google SEO Office Hours included a question about whether a security header confers an influence on ranking. It&#8217;s not as far-fetched as it seems at first glance because a security header like the HSTS header plays an important role in ensuring a secure HTTPS connection, and HTTPS is a lightweight Google ranking signal. HSTS security header A header is a response that a server provides to a browser (or crawler). The most well-known&#8230; <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4649","post","type-post","status-publish","format-standard","hentry","category-seo-news"],"_links":{"self":[{"href":"https:\/\/afreeurl.com\/index.php?rest_route=\/wp\/v2\/posts\/4649","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afreeurl.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afreeurl.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afreeurl.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afreeurl.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4649"}],"version-history":[{"count":0,"href":"https:\/\/afreeurl.com\/index.php?rest_route=\/wp\/v2\/posts\/4649\/revisions"}],"wp:attachment":[{"href":"https:\/\/afreeurl.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4649"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afreeurl.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4649"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afreeurl.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4649"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}