Support
Loading...

Chrome 154 Enables HTTP Prompts: Check Your Website’s HTTPS

3 October 2026

Chrome 154, released September 22, 2026, enables a default prompt for insecure HTTP connections. Website owners should confirm that their public domains load over HTTPS, use valid certificates, and avoid insecure links that can interrupt a visitor’s journey.

Google’s Chrome 154 release notes list “Ask before HTTP on by default” as a privacy and security change. The stable release date is September 22, 2026. Chrome now prompts users by default when they connect to a site over insecure HTTP; organizations can manage the behavior through Chrome’s enterprise policy. Google had earlier described the intended default as a setting focused on public websites, with a warning when a secure connection is unavailable.

What changes for visitors?

HTTP sends a web connection without the protection of HTTPS. Chrome’s change adds friction when a visitor reaches a public site that cannot use a secure connection. It does not mean every HTTP link will show a warning on every visit: Chrome tries HTTPS first, and Google says it avoids repeatedly warning people about a regularly visited insecure site. The exact experience can also depend on browser version and managed settings.

This is a browser connection change, not a change to domain registration or DNS records. A working domain can still lead to a poor visitor experience if its website remains HTTP-only.

What website owners should check

  1. Test both your main domain and www. Open each address with https:// and confirm it reaches the intended website. Check any other hostnames you share with customers.
  2. Check the certificate. Confirm the browser trusts it, that it covers the hostname, and that renewal is in place. If you need a certificate, compare the SSL certificate options at NicNames. Our guide to avoiding SSL certificate expiry explains why renewal matters.
  3. Review redirects and links. If someone types an HTTP address or follows an old link, confirm it reaches the secure page. Update links you control to point directly to HTTPS, including navigation, email templates and prominent calls to action.
  4. Check page resources. Images, scripts and forms should load securely so the page works as intended over HTTPS.

For a broader explanation of certificates and how they support HTTPS, see our SSL certificate guide. The immediate priority is a simple real-browser check of every public address customers use.

Share this article:
Ask Jexi