Why Are Both HTTP and HTTPS Versions of My Local Pages Appearing in Google?

HTTP and HTTPS URLs can be treated as duplicate versions of the same page when both remain accessible, so the site should provide clear and consistent signals about which secure URL is the preferred version.

Are HTTP and HTTPS different URLs?

Yes. http://example.com/locations/west/ and https://example.com/locations/west/ are different addresses.

If both return the same page with a 200 status, Google can cluster them as duplicates and choose a representative URL. That is ordinary canonicalisation, described in What is canonicalization.

Is duplicate accessibility automatically a spam violation?

No. Accessible HTTP and HTTPS copies are a technical consistency issue, not an automatic spam verdict.

Google documents reasons to specify a canonical, including consolidating signals and simplifying metrics. It does not treat an open HTTP copy as keyword stuffing or a deceptive practice by itself. Do not noindex the HTTP URL as the first move when a redirect would state the preference more clearly.

Which version should normally be preferred?

HTTPS, where it is correctly implemented.

Google currently prefers HTTPS pages over equivalent HTTP pages as canonical, except when there are issues such as an invalid SSL certificate, insecure dependencies other than images, the HTTPS page redirecting to or through HTTP, or a rel=canonical on the HTTPS page that points at HTTP. Those exceptions can cause Google to prefer HTTP strongly. Source: How to specify a canonical URL.

Should HTTP redirect to HTTPS?

Yes, use a permanent redirect where the HTTPS page is the intended version.

Google currently lists redirects as a strong canonical signal and recommends HTTP-to-HTTPS redirects, a canonical from HTTP to HTTPS, and HSTS to reinforce the preference. HSTS cannot override a bad certificate or an HTTPS-to-HTTP redirect. After a redesign, leftover HTTP copies are a common accident: Local SEO after a website redesign. Missing redirects on changed paths are URL changes without redirects.

Should canonical tags use HTTPS?

Yes. Keep canonical signals consistent with the secure URL you want indexed.

Google recommends a self-referential canonical on the preferred page and absolute URLs. Do not specify HTTP in the sitemap and HTTPS in the tag. If Google still chooses a different path on your own host after the protocol is aligned, that is Google choosing a different canonical location page.

Should XML sitemaps contain HTTP URLs?

Prefer canonical HTTPS URLs.

Google currently says not to include the HTTP version of your pages in your sitemap or hreflang annotations rather than the HTTPS version. Sitemap inclusion is a weaker signal than a redirect, but it should not advertise the copy you are trying to retire.

Update them to the HTTPS URLs you want treated as canonical.

Google currently says that linking consistently to the URL you consider canonical helps it understand your preference. Navigation, locators and in-content links that still use HTTP keep the duplicate alive.

What if GBP links to the HTTP version?

Use the authoritative current URL — normally the HTTPS location or homepage you want customers to open.

The profile website field is a customer destination. An HTTP link may still redirect, but it is an unnecessary hop and a mixed signal if Search Console is already clustering both versions.

Could mixed signals affect tracking?

Yes. They can fragment reporting.

Google lists simplifying metrics as a reason to specify a canonical. HTTP and HTTPS sessions, hostnames and referral paths can split GA4 and Search Console data even when customers see “the same page.” Fix the protocol pair before you treat the split as a lead-quality mystery. A broader technical pass belongs in a Local SEO audit.

HTTP → HTTPS Diagnostic Checklist

Flow from HTTP URL through permanent redirect, HTTPS URL, canonical, internal links and sitemap to a preferred Search URL.
HTTP versus HTTPS is a protocol-pair problem. Google choosing a different path on the same host is a separate canonical diagnosis.
  • HTTP location and service URLs permanently redirect to HTTPS.
  • The HTTPS certificate is valid and matches the host.
  • Self-referencing canonicals use the HTTPS URL.
  • Internal links and the sitemap list HTTPS only.
  • The Business Profile website field uses the current HTTPS URL.
  • Search Console is inspected for user-declared versus Google-selected canonical.

What not to assume

  • That both versions in a report mean a manual penalty.
  • That a canonical tag alone is enough while HTTP still returns 200.
  • That HSTS will fix an HTTPS-to-HTTP redirect.
  • That this is the same problem as two different location templates competing.

What not to do

  • Do not noindex every HTTP URL as the first step.
  • Do not point HTTPS canonicals at HTTP.
  • Do not leave HTTP in the sitemap “for coverage.”
  • Do not treat an invalid certificate as a content problem.

Practical options

  1. Confirm HTTP still serves content.
  2. Fix the certificate if HTTPS is broken.
  3. Add permanent HTTP-to-HTTPS redirects.
  4. Align canonicals, internal links, sitemap and the profile website field.
  5. Request inspection on a few important location URLs, then wait for recrawl.

When professional help makes sense

Help is useful when a CMS, CDN or load balancer serves both protocols, or when HTTP still wins because of a certificate or redirect loop. Nobody can force Google to select a URL.

Sources and further reading

Both secure and non-secure local URLs appearing in search data?

Otepsphere can review redirects, canonicals, internal links and sitemap signals to identify conflicting URL versions.

Contact Otepsphere

Who writes this

This page is published by Otepsphere, a specialist Local SEO consultancy. A named founder biography, photograph and professional profiles will be added here only when they have been verified. Until then, treat Otepsphere as the responsible organisation rather than a fictional expert.

Request SEO Audit