What Electricians With Locked Websites Do Differently
89.7% of electrician sites serve over HTTPS, which is nearly the weakest showing of the 47 trades I ranked. Four ordinary habits separate the sites that never break.
How many separate places is your web address written down this morning?
Count the van first, because an electrician’s van is a billboard that drives itself. Then the invoice template. A fridge magnet from four years ago, two directory listings you’ve never logged into, and a Facebook page your sister-in-law built for you in 2016.
Every one of those is a door into your website. Each one gets tried by a stranger eventually, and you have no idea which of them opens onto something pleasant.
I’ve lost a lot of Mondays to this one small thing. Not the clever parts of a website. Just whether the plain old address still takes a person somewhere safe.
It’s the dullest work I do, and it saves more jobs than any of the interesting work.
Where the padlock stands in this trade
89.7% of the electrician websites I audited serve over HTTPS, against 94% of every small business site in my sample.
HTTPS is what earns your page the padlock, and Google’s guide for site owners is blunt about how far to take it: browsers ought to be sent to the secure copy every single time, even when the link a visitor tapped pointed at the plain one.
Your trade runs the quickest pages I test, which makes the padlock odder still. It’s why the lock goes ahead of speed when I put an electrician’s cheap fixes in order.
None of the habits below is clever, which is the annoying thing about a trade landing 46th of the 47 I ranked on that column.
The trades at the top of it aren’t more technical than you are. I’ve been inside plenty of their websites and there’s nothing in there an electrician couldn’t follow.
They’ve just got four habits, and none of the four costs money.
One account, with your own name on it
The clients who never ring me in a panic keep the domain, the hosting and the certificate together in one account, in the owner’s name, with the owner’s own email on the recovery.
The ones who do ring me have the domain registered at one company under a nephew’s address, hosting somewhere else entirely, and a certificate someone bought once on a card that expired two employers ago.
When a padlock vanishes on a Sunday, the first owner makes one phone call. The second starts hunting for a man he hasn’t spoken to since 2019.
I’ve been on the other end of that hunt. A client rang me about a site I built for her husband, and it turned out he’d bought the address himself years earlier, on an account tied to a work email. He left that job in 2018.
We got it back. It took nine days, two forms and a scan of his driver’s license, and I wouldn’t wish any of it on you.
Which of those two is you? There’s a quick way to find out. Who could log into your website and change the phone number on it this afternoon, without asking anyone for permission?
If that answer takes you more than a few seconds, the next three habits can’t help you yet. Sort this one first.
Renewal that nobody has to remember
Your certificate expires. Expiring is the entire design of the thing, and there’s no version you can buy that lasts forever.
The sites I find sitting behind a warning are almost never sites that never had one. They’re sites where renewing it was one person’s personal responsibility, and that person moved on without telling you.
So ask your host the question I ask on every handover. Does it renew itself?
An answer with a date in it is a trap, because that date will land during a week when you’re up a ladder with your phone in the van.
An answer of “automatically, we handle it” is what the tidy ones have, and it’s usually included in hosting they were already paying for.
One of my own clients went dark on a Saturday in July. His renewal had bounced off a card that expired, nobody opened the email about it, and by lunchtime his site was throwing a full page warning at every person who tapped it.
I fixed it in ten minutes. The ten minutes were never the problem.
The problem was the morning of customers who had already made up their minds about him. How many is that, on the busiest Saturday of your summer? Neither of us will ever know.
Testing the address you never type
You type your own address one particular way, out of your own history, on your own laptop, and it behaves beautifully every single time.
Your customer types whatever is printed on something. Printed things are old.
So the tidy ones check all four versions of the address: with the www on the front and without it, plain and locked. It’s the first thing I do when a new client’s file lands on my desk, and all four should arrive at the same locked page with no warning anywhere.
Google recommends a permanent redirect from old addresses to current ones whenever anything about a site’s addresses changes, so search engines follow you across instead of guessing. That instruction is the redirect, it lives in a settings panel, and it’s the piece that gets skipped.
81.2% of electrician sites catch a visitor on the plain address and put him on the locked one, where 88% across everything I audited do.
You’re in company, at least. Hotels and restaurants serve a locked page as well as anybody and then finish dead last of forty-seven at walking people over to it.
Nobody spots that gap on their own site, because nothing about it looks broken from where you’re standing. I only find it because I go looking on purpose.
Checking again after the rebuild
Redirects die during a redesign. Across everything I’ve audited, that’s the most common way a perfectly good site turns into a warning.
New host, new folders, new everything, and the setting that used to catch the printed address stayed behind on a server nobody pays for anymore.
I find these in the week after a launch, and never once because the owner spotted it. It’s me, or it’s a customer being polite.
When did your site last change hands, or hosts, or shape? Whoever did that work tested the addresses they type themselves, and I’d bet nobody tested the one printed on your invoices.
So the fourth habit is dull as dishwater. After anything about your site changes, you or someone you trust types the printed address again and watches what happens.
Put it on the same list as the final invoice. It takes eleven seconds and it’s the only quality check on that list a non-technical person can perform alone.
None of this is a purchase
Notice what none of my tidy clients did. They didn’t buy a security product, hire a consultant, or rebuild anything.
They set up four boring arrangements and then stopped thinking about the subject entirely, which is the right amount of thinking for a person whose actual job is electrical work. The other jobs that keep a small site out of trouble are arrangements too, not purchases. How much of your week would you like to spend thinking about certificates? None is the right answer, and none is what my tidiest clients spend.
The electrician sites I keep as examples aren’t sophisticated about any of this. They’re tidy, and tidy survives a decade of neglect better than clever does.
A lock is still only a lock, mind you. Denver closes its front door better than any city I check, and I’ve set out what that buys an owner and what it doesn’t.
It’s also why the websites I build for electricians come with the hosting attached. Not out of generosity. It’s so the certificate stops being a person’s yearly responsibility, mine included.
If you’d rather have someone else look at all four, send me the address and I’ll go through the list properly.
But do one thing before you close this tab. Log into wherever your site is hosted, find the word certificate, and see whether the page says the renewal happens on its own or names you a date. If it names a date, put that date in the calendar beside your insurance renewal.