HTTPS Badge

A badge that confirms two concrete things about your home page: it answers over HTTPS, and a visitor who types the plain http:// address is sent to the encrypted version rather than left on an unencrypted page.

Website & Security SVG badge Checked by A2Z server Free · no ads

Customize your badge

The badge is checked for this domain. Enter the site you will show it on.
Style
Colours
Size

Live preview

Checked live by A2Z
HTTPS Badge for a2z.tools

Showing the badge for a2z.tools. Enter your domain to see yours.

Embed code

The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".

Works with

How it works

A2Z requests both http://your-domain/ and https://your-domain/ through its SSRF-guarded fetcher, following each redirect hop itself, and records whether the HTTPS request gets a response and whether the plain-HTTP request ends on an https:// address. "Enforced" means both are true (or plain HTTP is not served at all); "not enforced" means HTTPS works but the plain address stays unencrypted, which is exactly the gap HSTS and a permanent redirect close.

What is checked

  • HTTPS reachable: https://domain/ returns any HTTP response
  • Enforced: the http://domain/ request redirects (301/302/307/308) to an https:// URL, or port 80 does not answer
  • Cached for six hours

Limitations

  • Only the home page URL is requested; individual paths could still be served over HTTP.
  • A redirect that goes through several HTTP hops before reaching HTTPS still counts as enforced.
  • It does not check certificate validity - see the SSL certificate badge.

Where publishers use it

  • Small business sites confirming a hosting migration to HTTPS
  • Web developers' portfolio footers
  • Compliance checklists that require HTTPS everywhere

Questions

My site uses HTTPS - why does the badge say not enforced?

Because a visitor who types http://your-domain is not redirected. Add a permanent (301 or 308) redirect from HTTP to HTTPS at the server or CDN, then consider HSTS.

Does this check every page?

No, only the home page address of the domain. Most sites apply the redirect site-wide, so the home page is a good indicator, but it is not proof for every path.

Is HTTPS enough on its own?

It protects data in transit between the visitor and your server. It says nothing about the security of the application, its data storage or its other servers.

Does the badge prove my site is safe?

No. It confirms that A2Z reached the domain over HTTPS with a certificate browsers accept at the time of the check. It does not scan for malware, vouch for the business behind the site, or test every page.

What happens when my certificate renews?

Nothing changes on your page: the badge is re-checked on its next refresh and keeps showing HTTPS as long as the new certificate is valid for the domain. If a renewal fails and the certificate expires, the badge reports the problem instead of a stale pass.

Sources

  1. RFC 9110 - HTTP Semantics (status codes and redirection) - IETF
  2. RFC 6797 - HTTP Strict Transport Security (HSTS) - IETF

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools HTTPS Badge
https://a2z.tools/https-checker
  • HSTS Badge

    Website & Security SVG badge

    Shows whether your site sends HTTP Strict Transport Security, with max-age and preload.

    Get code
  • SSL Certificate Badge

    Website & Security SVG badge

    A live badge showing that your SSL certificate is valid, trusted and how many days it has left.

    Get code
  • Security Headers Badge

    Website & Security SVG badge

    Counts how many of six key HTTP security headers your site sends - e.g. "5 / 6".

    Get code
  • SSL Expiry Badge

    Website & Security SVG badge

    A badge counting down the days until your SSL certificate expires.

    Get code
  • SPF Record Badge

    Website & Security SVG badge

    Shows whether your domain publishes an SPF record and how it ends (-all, ~all).

    Get code
  • DMARC Policy Badge

    Website & Security SVG badge

    Shows your domain's DMARC policy - p=reject, p=quarantine or p=none.

    Get code

Preview