Handbook / Module 5 / Lesson 2

HTTPS Validation & Mobile Usability Reports

Ensure 100% secure protocol compliance with the HTTPS report, resolve mixed content warnings, and eliminate mobile usability friction points.

Beginner 16 min read #HTTPS #SSL #Security #Mobile Usability #Mixed Content

Security & Mobile Experience: Core Baseline Signals

Modern search algorithms treat transport-layer security (HTTPS) and responsive viewport adaptability as baseline prerequisites. Google Search Console includes dedicated reporting modules to monitor protocol integrity and viewport issues.


Deconstructing the HTTPS Report

Located under Experience > HTTPS, this report audits whether the URLs Google serves on SERPs are served securely over valid TLS/SSL certificates.

┌────────────────────────────────────────────────────────────────────────┐
│                        HTTPS STATUS BREAKDOWN                          │
│                                                                        │
│  [✓] HTTPS is valid (Served securely)                                  │
│  [!] HTTPS not evaluated (Low traffic, queued for crawl)              │
│  [X] HTTPS not valid (Active security failure)                         │
└────────────────────────────────────────────────────────────────────────┘

Common HTTPS Report Failures:

  1. Certificate Invalid / Expired: Your TLS certificate expired or does not cover subdomains (SSL_ERROR_BAD_CERT_DOMAIN).
  2. HTTP URL in Sitemap: Your XML sitemap mistakenly points to http:// instead of https://.
  3. Redirect to Insecure Protocol: An HTTPS URL redirects back to an insecure HTTP destination.
  4. Mixed Content Inclusions: The page is served over HTTPS, but includes insecure HTTP script tags or stylesheet assets (http://...).
  5. Canonical Points to HTTP: The <link rel="canonical"> specifies an http:// destination.
# Example: Enforcing HSTS and HTTPS Redirection in Nginx
server {
    listen 80;
    server_name example.com www.example.com;
    return 301 https://example.com$request_uri;
}

server {
    listen 443 ssl http2;
    server_name example.com;

    # Enforce HTTP Strict Transport Security
    add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
}

Mobile Usability: The Smartphone-First Standard

With Google’s 100% rollout of Mobile-First Indexing, Googlebot Smartphone is the primary user agent evaluating your pages.

Common Mobile Usability Faults:

  • Text too small to read: Font size is below 12px, requiring users to pinch-to-zoom to read body copy.
  • Clickable elements too close together: Touch targets (buttons, links) lack adequate spacing (less than 48px × 48px touch boundary), causing accidental clicks.
  • Content wider than screen: Horizontal scrollbars generated by fixed-width elements (e.g. width: 1200px on a desktop table) exceeding viewport boundaries.
  • Viewport not set: Missing <meta name="viewport" content="width=device-width, initial-scale=1.0">.
Use Tailwind's utility classes to guarantee compliant touch targets: ```html ```

Lab Challenge: HTTPS & Viewport Check

1. Open the **HTTPS** report in Search Console. 2. Are any URLs listed under "HTTPS is not valid"? If so, what is the reported sub-reason? 3. Inspect your site's primary layout template. Verify that the mobile viewport `` tag is properly declared in ``.