A CA certificate proves a website is who it says it is

A CA certificate (Certificate Authority certificate) is a digital document that a trusted organization issues to confirm a website's identity. When you visit a website with HTTPS in the address bar, that padlock icon means a CA certificate is working in the background to verify the site is legitimate and not an imposter.

The certificate acts like an ID card for the website. It contains the website's name, the organization that owns it, an expiration date, and a digital signature from the Certificate Authority — the organization that issued it. Your browser checks this signature automatically every time you land on the page. If the signature is valid and the website name matches, the connection is secure. If something doesn't match, your browser warns you.

Without CA certificates, anyone could create a fake website that looks identical to your bank or email provider, and you would have no way to know the difference. The certificate is what makes that impersonation detectable.

Key Takeaways

  • A CA certificate is issued by a trusted Certificate Authority to prove a website's real identity and ownership.
  • Your browser automatically checks the certificate every time you visit a secure website, looking for a valid signature and a matching domain name.
  • If a certificate is missing, expired, or doesn't match the website address, your browser displays a warning and may block the connection.
  • Websites must renew their certificates before they expire, usually every one to three years depending on the certificate type.

How your browser verifies a CA certificate

When you type a web address into your browser and press Enter, your browser connects to that website's server. The server sends back its CA certificate as part of the handshake. Your browser then performs several checks in seconds without you seeing any of it.

First, your browser checks whether the Certificate Authority that signed the certificate is one it trusts. Your browser comes pre-loaded with a list of trusted Certificate Authorities — organizations like DigiCert, Let's Encrypt, Sectigo, and others. If the signature came from one of these trusted authorities, the check passes. If it came from an unknown or self-signed authority, your browser flags it as suspicious.

Second, your browser compares the website address you typed (or clicked) with the domain name listed in the certificate. If you visit example.com but the certificate says the site belongs to example-phishing.com, your browser stops and shows you a warning. This prevents attackers from using a valid certificate for one domain to impersonate another.

Third, your browser checks the expiration date. Certificates have an end date printed on them. If today's date is past that date, the certificate is expired and no longer valid, even if it was issued by a trusted authority.

What happens when a certificate is missing or invalid

If you visit a website and something is wrong with its certificate, your browser will not silently proceed. Instead, you will see a warning message — usually a red screen or a prominent alert that says the connection is not secure or that the certificate cannot be verified.

The most common reasons for these warnings are: the certificate has expired, the domain name in the certificate does not match the website you are visiting, the certificate was issued by an authority your browser does not recognize, or the certificate has been revoked (cancelled by the Certificate Authority because the website lost ownership of the domain or for security reasons).

If you see this warning on a website you trust — like your bank or email — do not enter your password or any personal information. Contact the organization directly using a phone number from their official website or a statement you received in the mail. The warning usually means either the website is temporarily misconfigured, the certificate renewal was missed, or someone is attempting to intercept your connection.

The difference between certificate types

Not all CA certificates are identical. They come in different levels of validation, and the level affects how much verification the Certificate Authority performed before issuing the certificate.

A Domain Validated (DV) certificate is the fastest and cheapest type. The Certificate Authority only checks that the person requesting the certificate controls the domain name — usually by asking them to add a special code to the website or respond to an email sent to the domain. DV certificates are common for blogs, small websites, and personal projects. They provide the same encryption as other certificates, but they do not verify the organization's legal identity.

An Organization Validated (OV) certificate requires more proof. The Certificate Authority verifies that the organization requesting the certificate actually exists, is registered with the government, and owns the domain. OV certificates take longer to issue but provide stronger proof of identity. They are common for business websites and e-commerce sites.

An Extended Validation (EV) certificate requires the most thorough verification. The Certificate Authority performs background checks, confirms the organization's legal status, and verifies that the person requesting the certificate has authority to do so. EV certificates are the most expensive and take the longest to issue, but they provide the highest level of proof. Some browsers display the organization's name in the address bar when an EV certificate is in use, making it immediately obvious who owns the site.

How long certificates last and when they need renewal

CA certificates have an expiration date printed on them. Most certificates are valid for one to three years from the date they are issued. After that date passes, the certificate is no longer valid, and the website must obtain a new one.

Website owners are responsible for renewing their certificates before they expire. Many Certificate Authorities send reminder emails as the expiration date approaches, but it is the website owner's job to act on those reminders. If a certificate expires and is not renewed, visitors will see a browser warning and may not be able to access the site at all.

Some websites use automated renewal systems that request a new certificate weeks or months before the old one expires, so the transition happens without anyone noticing. Other websites renew manually. Either way, the goal is to have a new valid certificate in place before the old one runs out.

Why Certificate Authorities are trusted

The entire system depends on Certificate Authorities being trustworthy. If a Certificate Authority issued certificates to anyone who asked, without verifying their identity, the whole security system would fall apart. An attacker could get a certificate for your bank's domain and intercept your connection.

To prevent this, Certificate Authorities are heavily regulated. They must follow strict rules set by browser makers and industry standards. They undergo regular audits to prove they are following those rules. If a Certificate Authority is caught issuing certificates improperly, browsers remove it from their trusted list, and all its certificates become invalid overnight.

This is why your browser comes with a pre-loaded list of trusted Certificate Authorities. That list is maintained by browser makers like Mozilla (Firefox), Google (Chrome), and Apple (Safari). They add new Certificate Authorities only after verifying they meet the required standards, and they remove ones that fail audits or violate the rules.

Frequently Asked Questions

What does the padlock icon mean?

The padlock icon in your browser's address bar means the website has a valid CA certificate and your connection is encrypted. The website's identity has been verified by a trusted Certificate Authority. A padlock does not mean the website is safe or trustworthy in every way — it only means the connection itself is secure and the site is who it claims to be.

Can I visit a website without a CA certificate?

You can attempt to, but your browser will show you a warning first. Most modern browsers make this difficult on purpose, because visiting an unencrypted site (HTTP instead of HTTPS) means your data is not protected and the site's identity is not verified. Some websites still use HTTP for non-sensitive pages, but any page where you enter a password or payment information should always have HTTPS and a valid certificate.

If a website has a CA certificate, is it definitely safe?

A valid CA certificate means the website's identity is verified and your connection is encrypted, but it does not may provide the website itself is safe or legitimate. A scam website can have a valid certificate. The certificate only proves who owns the site, not whether the site's owner has good intentions. Always verify you are on the correct website by checking the address bar, and be cautious about what information you share.

Why did my bank's website show a certificate warning?

This usually means the certificate has expired, the domain name in the certificate does not match the address you typed, or the certificate was revoked. Do not enter your password. Contact your bank using a phone number from your statement or their official website to report the issue. It may be a temporary misconfiguration, or it could indicate a problem that needs immediate attention.

How much does a CA certificate cost?

Prices vary widely depending on the certificate type and the Certificate Authority. Domain Validated certificates can cost anywhere from free (through services like Let's Encrypt) to $50 to $100 per year. Organization Validated and Extended Validation certificates typically cost $100 to $500 or more per year. Many hosting providers include a free basic certificate with their plans.