HTTPS Badge
A badge that confirms two concrete things about your home page: it answers over HTTPS, and a visitor who types the plain http:// address is sent to the encrypted version rather than left on an unencrypted page.
Live preview
Checked live by A2ZShowing the badge for a2z.tools. Enter your domain to see yours.
Embed code
The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".
Works with
How it works
A2Z requests both http://your-domain/ and https://your-domain/ through its SSRF-guarded fetcher, following each redirect hop itself, and records whether the HTTPS request gets a response and whether the plain-HTTP request ends on an https:// address. "Enforced" means both are true (or plain HTTP is not served at all); "not enforced" means HTTPS works but the plain address stays unencrypted, which is exactly the gap HSTS and a permanent redirect close.
What is checked
- HTTPS reachable: https://domain/ returns any HTTP response
- Enforced: the http://domain/ request redirects (301/302/307/308) to an https:// URL, or port 80 does not answer
- Cached for six hours
Limitations
- Only the home page URL is requested; individual paths could still be served over HTTP.
- A redirect that goes through several HTTP hops before reaching HTTPS still counts as enforced.
- It does not check certificate validity - see the SSL certificate badge.
Where publishers use it
- Small business sites confirming a hosting migration to HTTPS
- Web developers' portfolio footers
- Compliance checklists that require HTTPS everywhere
Questions
My site uses HTTPS - why does the badge say not enforced?
Because a visitor who types http://your-domain is not redirected. Add a permanent (301 or 308) redirect from HTTP to HTTPS at the server or CDN, then consider HSTS.
Does this check every page?
No, only the home page address of the domain. Most sites apply the redirect site-wide, so the home page is a good indicator, but it is not proof for every path.
Is HTTPS enough on its own?
It protects data in transit between the visitor and your server. It says nothing about the security of the application, its data storage or its other servers.
Sources
- RFC 9110 - HTTP Semantics (status codes and redirection) - IETF
- RFC 6797 - HTTP Strict Transport Security (HSTS) - IETF
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools HTTPS Badge https://a2z.tools/https-checker
<a href="https://a2z.tools/https-checker">A2Z Tools HTTPS Badge</a>
[A2Z Tools HTTPS Badge](https://a2z.tools/https-checker)
HTTPS Badge by A2Z Tools - https://a2z.tools/https-checker
Related widgets
-
Shows whether your site sends HTTP Strict Transport Security, with max-age and preload.
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
Counts how many of six key HTTP security headers your site sends - e.g. "5 / 6".
-
A badge counting down the days until your SSL certificate expires.
-
Shows whether your domain publishes an SPF record and how it ends (-all, ~all).
-
Shows your domain's DMARC policy - p=reject, p=quarantine or p=none.