An SSL certificate encrypts the connection between your browser and a website

An SSL certificate is a small file that a website installs on its server to turn on encryption. When you visit a site with an SSL certificate, your browser and that server create an encrypted tunnel — anything you type (passwords, credit card numbers, messages) travels through that tunnel in scrambled form that only the server can read. Without it, that same information travels in plain text, readable to anyone intercepting the connection.

SSL stands for Secure Sockets Layer, though the technology has been updated and is now called TLS (Transport Layer Security). The terms are used interchangeably. You can tell a site has one because the address bar shows a padlock icon and the URL starts with https:// instead of http://. The "s" means secure.

The certificate also proves the website is who it claims to be. When you connect, your browser checks the certificate against a list of trusted certificate authorities — organizations that verify website ownership before issuing certificates. This prevents a scammer from setting up a fake site that looks identical to your bank's and intercepting your login.

Key Takeaways

  • An SSL certificate encrypts data traveling between your browser and a website's server, so passwords and payment information cannot be read if intercepted.
  • The padlock icon and https:// in the address bar show that a site has an active SSL certificate.
  • Certificate authorities verify that a website actually belongs to the organization claiming to own it, preventing impersonation.
  • Most websites now use SSL certificates as standard, and browsers warn you when a site lacks one.
  • SSL certificates must be renewed periodically — typically every one to three years — or the encryption stops working.

How the encryption actually works

When you first connect to a website with an SSL certificate, your browser and the server perform a handshake. The server sends your browser its certificate and a public key — a long string of characters. Your browser uses that public key to encrypt a message back to the server. Only the server's private key (which it keeps secret) can decrypt that message. From that point forward, both sides use a shared encryption key to scramble and unscramble everything you send and receive.

This happens automatically and takes less than a second. You do not have to do anything — your browser handles it. The encryption is strongest when both the certificate and the server software are up to date, which is why websites need to renew their certificates before they expire.

What an SSL certificate does not protect

An SSL certificate encrypts data in transit — the moment it leaves your device until it reaches the server. It does not encrypt data sitting on the server itself. If a website's database is breached, an SSL certificate will not prevent hackers from stealing the information stored there. That requires separate security measures like firewalls, access controls, and encryption at rest.

SSL also does not protect you from phishing. A scammer can buy an SSL certificate for a fake website that looks nearly identical to the real one. Your browser will show the padlock and https://, but you are still on the wrong site. Always check the full URL in the address bar and look for slight misspellings (like "amaz0n.com" instead of "amazon.com").

Why websites display the padlock icon

The padlock and https:// are visual signals that the connection is encrypted. Modern browsers started showing warnings when a site lacks an SSL certificate — usually a red warning page or a "Not Secure" label in the address bar. This pushed most websites to install certificates, because users avoid sites that look unsafe.

Some websites that do not handle sensitive information (like a blog or news site) may not have an SSL certificate, and that is usually fine. But any site asking for a password, payment information, or personal details should have one. If it does not, that is a red flag.

How often certificates need to be renewed

SSL certificates expire. Most last one to three years before they must be renewed. When a certificate expires, the encryption stops working and browsers show a warning. Website owners receive reminder emails from their certificate authority before expiration, but sometimes those reminders get missed or ignored.

If you visit a site and see a warning that the certificate has expired, the site's owner has not renewed it. This does not necessarily mean the site is unsafe — it usually just means they forgot or there was a delay in the renewal process. But it is a sign that the site may not be well-maintained, so proceed with caution before entering sensitive information.

Different types of SSL certificates

Certificate authorities issue different types of certificates depending on what a website needs to prove. A domain validation certificate confirms that someone owns the domain name — the authority sends a verification email to the domain owner and issues the certificate if they respond. This is the cheapest and fastest option, usually issued in minutes.

An organization validation certificate goes further and verifies that a real business owns the domain. The authority checks business records and may call to confirm. These take longer to issue (days to weeks) and cost more, but they show more trust — some browsers display the organization's name in the address bar.

A wildcard certificate covers a domain and all its subdomains (like mail.example.com, shop.example.com, and example.com all at once). A multi-domain certificate covers multiple unrelated domains in a single certificate. These are useful for large organizations running many websites.

What happens if a certificate is compromised

If a hacker steals a website's private key, they can decrypt traffic meant for that site or impersonate it. Certificate authorities maintain a list called the Certificate Revocation List (CRL) where they can mark a certificate as no longer trusted. Browsers check this list and will warn users if they encounter a revoked certificate.

Website owners can also request revocation if they suspect their certificate has been compromised. Modern browsers are increasingly moving away from checking the CRL (because it is slow) and toward a faster system called OCSP stapling, where the website itself tells your browser whether its certificate is still valid.

Frequently Asked Questions

Does an SSL certificate mean a website is completely safe?

No. An SSL certificate only encrypts the connection between you and the website — it proves the site is who it claims to be and protects your data in transit. It does not protect data stored on the server, prevent phishing, or may provide the website is legitimate. Always verify the URL and use strong passwords.

Can I use a website without an SSL certificate?

Yes, but you should not enter passwords or payment information on one. If a site asks for sensitive data and lacks https://, your information travels unencrypted and can be intercepted. Most modern browsers warn you when a site lacks a certificate, which is why most websites now have one.

Why do some sites still not have SSL certificates?

Older websites, abandoned sites, or sites that do not handle sensitive information may lack certificates. Some site owners simply have not updated. Since certificates are now inexpensive and many hosting providers include them free, lack of a certificate usually signals poor maintenance rather than cost.

What is the difference between http and https?

The "s" in https means the connection is encrypted with an SSL certificate. With http, data travels unencrypted. Your browser will warn you if you try to enter a password on an http site. Always look for https:// when entering sensitive information.

Do I need to do anything to use an SSL certificate?

No. Your browser handles SSL automatically. You do not need to install anything or take any action. Simply look for the padlock icon and https:// to confirm the connection is encrypted before entering sensitive information.