A digital certificate is a file that proves a website is who it claims to be
When you visit a website, your browser checks for a digital certificate — a small file the website sends to prove its identity. Think of it like a driver's license for a website. Just as a driver's license proves you are who you say you are, a digital certificate proves that the website you are visiting is actually owned and operated by the organisation behind it, not by someone pretending to be them.
The certificate contains the website's name, the organisation that issued the certificate, and a digital signature that proves the certificate has not been tampered with. Your browser automatically checks this signature against a list of trusted certificate issuers. If the signature is valid and the website name matches, you see a lock icon in your address bar. If something is wrong — the certificate has expired, the website name does not match, or the issuer is not trusted — your browser will warn you or block the connection.
Digital certificates work together with encryption to protect your connection. The certificate proves the website is legitimate, and encryption scrambles the data you send so only that website can read it. Without the certificate, encryption alone would not stop someone from setting up a fake website and encrypting your data to their server instead.
Key Takeaways
- A digital certificate proves a website's identity the same way a driver's license proves yours, and your browser checks it automatically every time you visit a secure site.
- The lock icon in your address bar means the website has a valid certificate and your connection is encrypted, but it does not mean the website is trustworthy — only that it is who it claims to be.
- Certificate issuers are companies that verify a website's ownership before issuing a certificate, and your browser trusts only issuers on its built-in list.
- A certificate includes an expiration date, and websites must renew them regularly or visitors will see a warning that the certificate has expired.
How your browser checks a digital certificate
Every time you load a website with HTTPS (the secure version of HTTP), your browser performs a quick verification in the background. The website sends its digital certificate, which contains the website's domain name, the organisation name, and a digital signature created by the certificate issuer. Your browser checks three things: whether the certificate issuer is on its trusted list, whether the domain name in the certificate matches the website you are visiting, and whether the certificate has expired.
If all three checks pass, the lock icon appears and your connection is secure. If the domain name does not match — for example, you are visiting amazon.com but the certificate says amaz0n.com — your browser will show a warning. If the issuer is not on the trusted list, or if the certificate has expired, you will see a red warning screen before you can proceed. These warnings exist because a mismatch usually means you are being redirected to a fake website.
The trusted list of certificate issuers is built into your browser and your operating system. Companies like DigiCert, Sectigo, and GlobalSign are on this list because they have proven they verify website ownership carefully before issuing certificates. If a new issuer is not on the list, your browser will not trust its certificates, even if they are technically valid.
What information a digital certificate contains
A digital certificate is a structured file that holds specific pieces of information about the website and the organisation behind it. The most important field is the Common Name or Subject Alternative Name, which lists the domain name the certificate is valid for — for example, www.example.com or *.example.com (the asterisk means any subdomain). The certificate also includes the organisation's legal name, the city and country where it is registered, and contact information for the certificate holder.
Every certificate has an issue date and an expiration date. Most certificates are valid for one year, though some last two or three years. The certificate also contains the name and digital signature of the issuer — the company that verified the organisation's identity and created the certificate. Finally, the certificate includes a public key, which is the encryption tool your browser uses to scramble data before sending it to the website. Only the website's private key can unscramble it.
The difference between certificate types
Not all digital certificates require the same level of verification. A Domain Validated (DV) certificate only proves that someone controls the domain name — the issuer sends a verification email or checks a DNS record to confirm. This takes a few minutes and costs very little, so most small websites and blogs use DV certificates. The lock icon looks the same as any other certificate, but the organisation name does not appear in the certificate details.
An Organisation Validated (OV) certificate requires the issuer to verify that the organisation actually exists and is registered with the government. This takes a few days and costs more, but it proves the website is run by a real business. When you click the lock icon, you can see the organisation's legal name and address.
An Extended Validation (EV) certificate requires the most thorough verification — the issuer checks business registration, ownership, and sometimes calls the organisation directly. These certificates are expensive and take weeks to issue, so only large financial institutions and major retailers typically use them. In some older browsers, EV certificates displayed the organisation name directly in the address bar, though most modern browsers now treat them the same as OV certificates.
Why websites need to renew certificates regularly
Digital certificates expire because security standards and encryption methods improve over time. A certificate issued five years ago used encryption that was considered secure then but might be weaker now. By requiring renewal, the system forces websites to update to current security standards. Renewal also gives certificate issuers a chance to re-verify that the organisation still owns the domain and is still in business.
When a certificate expires, your browser will show a warning — usually a red screen saying "Your connection is not private" or "Certificate expired." This does not mean the website is dangerous; it usually just means the website owner forgot to renew. However, you should not enter passwords or payment information on a site with an expired certificate, because you cannot verify you are actually connected to the legitimate website.
Most website owners set up automatic renewal so their certificates renew a few weeks before expiration. Some use free certificate services like Let's Encrypt, which issues certificates valid for 90 days and automates the renewal process. Others pay for certificates from commercial issuers and renew them manually each year.
What the lock icon actually tells you
The lock icon in your address bar is often misunderstood. It means the website has a valid digital certificate and your connection is encrypted — data traveling between your browser and the website is scrambled. It does not mean the website is safe, trustworthy, or run by good people. A scam website can have a valid certificate. A website selling counterfeit goods can have a valid certificate. The lock icon only proves identity and encryption, not intent.
To decide whether to trust a website, you need to use other judgment: Does the website have contact information and a physical address? Does it have reviews from other users? Does it ask for unusual information or pressure you to act quickly? A valid certificate is a necessary condition for a safe website, but it is not sufficient by itself. Think of it as a locked door — it proves the door is secure, but it does not tell you who is on the other side.
Common certificate problems and what they mean
If your browser shows a certificate warning, one of a few things has happened. The most common is that the certificate has expired and the website owner has not renewed it yet. This is usually harmless but means the website is not being actively maintained. The second is a domain name mismatch — you typed a URL or clicked a link that does not match the domain in the certificate. This sometimes happens with redirects or subdomains and is usually not a problem, but it can indicate you are being redirected to a fake site.
The third is an untrusted issuer — the certificate was issued by a company your browser does not recognise. This is rare on mainstream websites but common on internal corporate networks or very new websites. The fourth is a self-signed certificate, which means the website issued its own certificate instead of buying one from a trusted issuer. This is a red flag on a public website but normal on internal tools or development servers.
If you see a certificate warning on a website you use regularly, contact the website's support team and ask them to renew their certificate. Do not ignore the warning and proceed anyway, especially if you are about to enter a password or payment information.
Frequently Asked Questions
Does a lock icon mean a website is safe to buy from?
The lock icon means your connection is encrypted and the website's identity is verified, but it does not mean the website is honest or trustworthy. A scam site can have a valid certificate. Before entering payment information, check for contact details, read reviews, and look for signs the site is legitimate — not just that it has encryption.
What happens if I ignore a certificate warning and visit the site anyway?
Your browser will let you proceed if you click through the warning, but you should not enter passwords or payment information. The warning usually means either the certificate expired (harmless but sloppy) or something is wrong with the domain name (potentially dangerous). If it is a site you use regularly, contact them to fix it first.
Can I see what information is in a website's certificate?
Yes. Click the lock icon in your address bar, then click "Certificate" or "Connection is secure," and your browser will show you the certificate details — the organisation name, issue date, expiration date, and issuer. This is useful for checking whether a certificate is about to expire or whether the organisation name matches what you expect.
Why do some websites use HTTP instead of HTTPS?
Websites that do not handle sensitive information sometimes skip HTTPS to save money or reduce server load. A blog or news site using HTTP is usually not a security risk, but you should never enter passwords or payment information on an HTTP site. Your browser will show "Not secure" in the address bar for HTTP sites.
Do I need to buy a certificate for my own website?
If your website collects any information from visitors — even just email addresses — you should use HTTPS with a certificate. Free services like Let's Encrypt issue certificates at no cost and automate renewal. Most web hosting providers also offer certificates as part of their service, either free or for a small annual fee.