A certification authority is an organization that verifies a website's identity and issues the digital certificate that makes HTTPS connections possible

When you visit a website with a padlock icon in your browser's address bar, a certification authority (CA) vouched for that site's identity. The CA checked that the organization requesting the certificate actually owns the domain name, then issued a digital document — the SSL/TLS certificate — that proves it. Your browser trusts the CA, so it trusts the certificate, so it trusts the encrypted connection to that website.

Without certification authorities, anyone could claim to be your bank or email provider. The CA system creates a chain of trust: you trust your browser's built-in list of CAs, the CAs verify websites, and websites prove their identity using certificates from those CAs. This is why HTTPS works at all.

Key Takeaways

  • A certification authority verifies that a website's owner actually controls the domain name before issuing a certificate.
  • Your browser comes with a list of trusted CAs built in; if a certificate comes from one of those CAs, the browser treats the connection as secure.
  • Different CAs perform different levels of verification — some check only that you control the domain, others verify your legal business identity too.
  • A certificate from an untrusted CA or an expired certificate will trigger a browser warning, even if the encryption itself is technically sound.

How a certification authority verifies a website

When a website owner requests a certificate, the CA performs verification steps to confirm they actually own or control the domain. The simplest method is domain control verification: the CA asks the applicant to prove they can modify the domain's DNS records or place a file on the website. If you can do either of those things, you control the domain.

More rigorous CAs also verify the legal identity of the business behind the domain. They may request business registration documents, check public records, or call a phone number listed in the business registration. This takes longer but provides stronger assurance that the certificate holder is who they claim to be.

Once verification is complete, the CA signs the certificate with its own private key. That signature is what makes the certificate trustworthy — your browser can verify the signature using the CA's public key, which is already stored in your browser's certificate store.

Why your browser trusts certain certification authorities

Your browser comes with a pre-installed list of trusted root CAs. These are organizations like DigiCert, Sectigo, GlobalSign, and Let's Encrypt that have been vetted by browser makers and operating systems. If a certificate is signed by one of these CAs, your browser accepts it without warning.

If a website presents a certificate from an unknown or untrusted CA, your browser will display a warning — typically a red error page or a broken padlock icon. This does not necessarily mean the connection is unsafe; it means your browser cannot verify the certificate's legitimacy because it does not recognize the CA that issued it.

Browser makers regularly audit CAs to ensure they follow security standards. A CA that issues certificates carelessly or fails security audits can be removed from the trusted list, which would break HTTPS for all websites using its certificates.

The difference between certificate validation levels

Not all certificates require the same amount of verification. Domain Validated (DV) certificates only confirm that the applicant controls the domain — they are the fastest and cheapest to obtain. A DV certificate proves the connection is encrypted but says nothing about the organization behind the website.

Organization Validated (OV) certificates require the CA to verify the legal business identity as well as domain control. The certificate displays the organization's name, so visitors can see who runs the site. OV certificates take longer to issue but provide stronger assurance of legitimacy.

Extended Validation (EV) certificates involve the most thorough verification, including legal business checks, phone verification, and sometimes in-person inspection. Historically, browsers displayed EV certificates with a green bar showing the organization name, though most modern browsers have removed this visual distinction.

What happens when a certificate expires or is revoked

Certificates have expiration dates, typically one to three years from issue. When a certificate expires, the CA no longer vouches for it. Your browser will warn you that the certificate is no longer valid, even if the website's encryption is technically working.

A CA can also revoke a certificate before its expiration date if the website owner requests it, if the private key is compromised, or if the CA discovers the certificate was issued in error. Revocation is checked through a system called OCSP (Online Certificate Status Protocol) or through CRL (Certificate Revocation List), though not all browsers check every time.

Website owners are responsible for renewing their certificates before expiration. Many CAs send reminders, and some offer automatic renewal, but ultimately it is the website's responsibility to maintain a valid certificate.

How certification authorities fit into the larger security picture

The CA system protects against impersonation but not against all threats. A valid HTTPS certificate proves you are connected to the real website, not a fake one set up by an attacker. It does not prove the website is trustworthy, that its software is secure, or that it will not steal your data.

A malicious website can obtain a valid certificate from a legitimate CA by proving it controls a domain it actually owns. The certificate will be technically valid even if the site's purpose is fraud. HTTPS encrypts the connection; it does not validate the site's intentions.

This is why certificate validation is one layer of security among many. Your browser also checks for malware, phishing sites, and outdated software. A valid certificate is necessary but not sufficient for safety.

Frequently Asked Questions

Can I get a certificate from a CA that is not in my browser's trusted list?

Yes, but your browser will warn visitors that the certificate cannot be verified. This is sometimes done intentionally for internal company networks or testing, but it is not suitable for public websites because visitors will see a security warning.

What does it mean if my browser shows a certificate warning?

It usually means the certificate is expired, issued by an untrusted CA, or does not match the domain name you are visiting. It can also mean the certificate chain is incomplete. Do not enter sensitive information on a site showing a certificate warning unless you have a specific reason to trust it.

Do I need an Organization Validated certificate or is Domain Validated enough?

For most websites, Domain Validated is sufficient — it proves the connection is encrypted and that you are reaching the real domain. Organization Validated provides extra assurance of legitimacy and is common for e-commerce and financial sites, but the encryption strength is the same.

Who decides which CAs are trusted?

Browser makers (Chrome, Firefox, Safari, Edge) and operating systems (Windows, macOS, Linux) maintain the lists of trusted CAs. They audit CAs regularly and can remove them if they fail security standards or issue certificates improperly.