An SSL certificate proves a website is who it claims to be and encrypts what you send it
An SSL certificate is a small file that a website installs on its server to do two things: prove its identity to your browser, and turn your connection into an encrypted tunnel so nobody between you and the website can read what you're sending. When you visit a site with an SSL certificate, your browser checks that certificate, confirms the website owns the domain you typed in, and then scrambles everything you type — passwords, credit card numbers, messages — so only that website can unscramble it.
You can see when a site has an SSL certificate by looking at the address bar. If the URL starts with https:// (not http://), and you see a padlock icon next to the address, the site has one. The "s" stands for "secure". Without an SSL certificate, the connection is http://, and anything you type travels in plain text that anyone on the same network can read.
SSL certificates are issued by trusted third-party companies called certificate authorities (CAs). The CA verifies that the person requesting the certificate actually owns or controls the domain, then signs the certificate with their own key. When your browser sees that signature, it trusts the certificate because it trusts the CA. This chain of trust is what stops someone from creating a fake certificate for a bank's website and fooling your browser into thinking it's real.
Key Takeaways
- An SSL certificate encrypts data between your browser and a website, so passwords and payment information cannot be read by others on the network.
- The padlock icon and https:// in the address bar show that a website has an SSL certificate and your connection is encrypted.
- Certificate authorities verify that a website owner actually controls the domain before issuing a certificate, preventing imposters from creating fake certificates.
- An SSL certificate does not mean a website is trustworthy or safe — it only means the connection is encrypted and the domain ownership is verified.
- Most websites now use SSL certificates by default, and browsers warn you when a site does not have one or when a certificate is invalid.
How your browser checks an SSL certificate
When you visit a website, your browser automatically downloads the SSL certificate from the server and runs several checks before it lets you proceed. First, it verifies the certificate authority's signature — that the CA that issued the certificate is one your browser trusts. Your browser comes with a built-in list of trusted CAs, and if the signature does not match any of them, the browser stops and shows you a warning.
Second, your browser checks that the domain name in the certificate matches the domain you typed in. If you visit example.com but the certificate says it belongs to example-phishing.com, your browser will warn you or block the connection. This is one of the main ways SSL certificates stop you from accidentally sending your login to a fake website that looks like the real one.
Third, your browser checks the certificate's expiration date. Certificates are issued for a set period — usually one to three years — and must be renewed before they expire. If a certificate has expired, your browser shows a warning. A website owner who lets a certificate expire is usually just careless, but it is still a sign something is wrong.
The difference between domain validation and extended validation certificates
Not all SSL certificates require the same level of checking. A domain validation (DV) certificate only confirms that the person requesting the certificate controls the domain — usually by responding to an email sent to an address at that domain, or by uploading a file to the website. This takes a few minutes and costs very little. Most websites use DV certificates.
An extended validation (EV) certificate requires the CA to do much more work: verify the company's legal registration, check that it is a real business with a real address, and sometimes call the company to confirm the request. This takes days or weeks and costs more. In return, some browsers used to show a green bar or the company name in the address bar to signal "this is a verified business." Most modern browsers have stopped showing this visual distinction, so the practical difference has shrunk.
For everyday purposes, a DV certificate is enough. The encryption is just as strong, and the domain verification is just as reliable. An EV certificate adds a layer of business verification, but that does not make the connection more secure — it just confirms the company behind the domain is real. If you are buying from a small business or a startup, a DV certificate is normal and not a sign of anything wrong.
What an SSL certificate does not protect you from
An SSL certificate encrypts the connection between you and a website, but it does not check whether the website itself is safe, honest, or what it claims to be. A phishing site — a fake website designed to steal your login — can have a valid SSL certificate. The certificate only proves that you are connected to the domain the certificate says you are connected to. It does not prove that domain is legitimate.
This is why the padlock icon can be misleading. Many people think "padlock means safe," but it really means "your connection is encrypted." A scammer can get an SSL certificate for scammer-bank.com, and your browser will show a padlock because the connection to scammer-bank.com is encrypted. You are protected from someone reading your password over the network, but not from sending your password to the wrong website in the first place.
An SSL certificate also does not protect you from malware, viruses, or a website that is hacked. If a legitimate website's server is compromised, the SSL certificate is still valid — the connection is still encrypted — but the website itself is now dangerous. You are still protected from someone intercepting your data in transit, but not from the website itself doing something malicious.
Why websites switched to SSL certificates
For years, most websites only used SSL certificates for pages where you entered sensitive information — a login page, a payment page, a form asking for your address. The rest of the site was unencrypted. Around 2016, major browsers and certificate authorities began pushing for HTTPS everywhere, the idea that every page on every website should be encrypted, not just the sensitive ones.
Google started ranking websites with SSL certificates higher in search results, which gave website owners a strong incentive to switch. Let's Encrypt, a free certificate authority launched in 2015, made it cheap and easy for small websites and nonprofits to get certificates. By 2020, most of the web had switched to HTTPS by default.
Today, if you visit a website without an SSL certificate, your browser shows a prominent warning: "Not Secure." This warning has made unencrypted sites so rare that most people now assume any site without HTTPS is dangerous, even if the site is just a blog or a static informational page where you are not entering any data. The shift was good for security overall — it means your browsing activity is harder to spy on — but it also means the padlock has become a visual habit rather than a meaningful signal of trustworthiness.
How to check an SSL certificate yourself
You can click on the padlock icon in your browser's address bar to see details about a website's SSL certificate. In most browsers, this opens a small popup showing the certificate authority that issued it, the domain it covers, and the expiration date. You can usually click through to see the full certificate details if you want to dig deeper.
If you are suspicious about a website, check three things: Does the domain in the certificate match the domain you typed in? Is the certificate issued by a well-known CA (not an unknown or suspicious-sounding one)? Has the certificate expired? If all three check out, the certificate is valid. That does not mean the website is safe or honest — it just means the certificate is real and the connection is encrypted.
If you see a warning that the certificate is invalid, expired, or does not match the domain, do not enter any sensitive information on that site. The warning means something is wrong — either the website owner made a mistake, or someone is trying to intercept your connection. Either way, it is a sign to leave.
Frequently Asked Questions
Does an SSL certificate mean a website is safe to shop on?
No. An SSL certificate only means your connection is encrypted and the domain ownership is verified. A phishing site or a scam store can have a valid SSL certificate. Before you enter payment information, check that the site is the real business (not a lookalike domain), read reviews, and look for contact information and a return policy. The padlock is necessary but not sufficient.
What happens if I visit a website without an SSL certificate?
Your browser will show a "Not Secure" warning in the address bar. You can still visit the site, but anything you type — including passwords — travels in plain text that anyone on the same network can read. Avoid entering any sensitive information on unencrypted sites, even if the site looks legitimate.
Can I get an SSL certificate for free?
Yes. Let's Encrypt issues free SSL certificates to anyone who can prove they control a domain. Many web hosting companies also include free certificates with their hosting plans. The encryption is just as strong as a paid certificate. The main difference is that free certificates usually expire after 90 days and must be renewed, while paid certificates last longer.
If a website has an expired SSL certificate, is it a scam?
Not necessarily. An expired certificate usually means the website owner forgot to renew it or did not notice it had expired. It is careless, but not necessarily malicious. That said, it is a sign the site is not being actively maintained, so be cautious about entering sensitive information until the owner fixes it.
Do I need to do anything to use an SSL certificate?
No. SSL certificates work automatically in the background. Your browser handles all the checking and encryption without you doing anything. You just see the padlock icon and https:// in the address bar. Website owners are the ones who install and maintain certificates on their servers.