A TLS certificate proves a website is who it claims to be

A TLS certificate is a digital document that a website installs on its server to prove its identity to your browser. When you visit a website with a TLS certificate, your browser checks that certificate before you send any sensitive information — passwords, credit card numbers, personal details. If the certificate is valid, your browser shows a padlock icon and the connection is encrypted. If something is wrong with the certificate, your browser will warn you or block the page entirely.

The certificate does two things at once. First, it encrypts the information traveling between your computer and the website's server so that no one snooping on the network can read it. Second, it confirms that the website you think you are visiting is actually the real one, not a fake site designed to steal your information. Without a TLS certificate, your data travels in plain text that anyone on the network can read, and you have no way to know if you are talking to the real bank or a criminal pretending to be the bank.

Key Takeaways

  • A TLS certificate encrypts data between your browser and a website's server so passwords and payment information cannot be read by others on the network.
  • The certificate also verifies that the website is genuine and not a fake site created to steal your information.
  • Your browser displays a padlock icon when a valid TLS certificate is in place, and shows a warning or blocks the page if the certificate is missing or invalid.
  • Websites obtain TLS certificates from certificate authorities, which are trusted organizations that verify the website's identity before issuing the certificate.
  • Most websites today use TLS certificates because browsers now flag sites without them as unsafe, and search engines rank them lower in results.

How a TLS certificate protects your connection

When you type your password into a website, that password needs to travel from your computer to the website's server. Without encryption, anyone connected to the same network — a coffee shop WiFi, a shared office network, or even someone intercepting traffic on the internet backbone — can read that password as it passes by. A TLS certificate encrypts the data using a mathematical key that only your browser and the website's server know, so the password becomes unreadable gibberish to anyone else.

The encryption happens automatically. You do not have to do anything. Your browser and the website's server exchange keys and set up the encrypted tunnel in the background before you even see the page load. Once the tunnel is open, everything you send — form data, login credentials, payment information — travels through that encrypted tunnel.

The second protection is verification. The certificate contains information about who owns the website, and it is signed by a certificate authority — an organization that has checked the website owner's identity. When your browser receives the certificate, it verifies the signature using the certificate authority's public key. If the signature is valid and the domain name in the certificate matches the website you are visiting, your browser trusts the connection. If the domain names do not match or the signature is forged, your browser stops and warns you.

Who issues TLS certificates and how they work

A certificate authority is an organization trusted by web browsers to issue and verify TLS certificates. Major certificate authorities include DigiCert, Let's Encrypt, Sectigo, and GlobalSign. When a website owner wants a TLS certificate, they request one from a certificate authority and provide proof of their identity — usually by showing ownership of the domain name or providing business registration documents.

The certificate authority verifies the information, then creates a certificate containing the website's domain name, the website owner's details, the certificate authority's digital signature, and an expiration date. The website owner installs this certificate on their web server. When your browser visits the site, the server sends the certificate to your browser. Your browser checks the certificate authority's signature using a public key it already has stored, confirms the domain name matches, and checks that the certificate has not expired. If all checks pass, the connection is trusted.

Certificates expire and must be renewed. Most TLS certificates are valid for one year, though some last longer. Website owners receive reminders when their certificate is about to expire and must renew it before that date. If a certificate expires and is not renewed, browsers will show a warning that the website is unsafe.

What the padlock icon means

When you see a padlock icon next to the website address in your browser's address bar, it means a valid TLS certificate is in place and your connection is encrypted. The padlock is your visual confirmation that the website has proven its identity to your browser and that your data is protected in transit.

Different browsers show the padlock in slightly different places. In Chrome, Firefox, Safari, and Edge, it appears to the left of the web address. Clicking on the padlock usually shows you details about the certificate — the organization name, the certificate authority that issued it, and the expiration date. Some websites display additional information like a green address bar or the organization name in the address bar itself, which indicates an extended validation certificate (a higher level of verification), though this is less common now.

If the padlock is missing or you see a warning triangle or an "X" instead, the website either has no TLS certificate, the certificate has expired, or the domain name in the certificate does not match the website you are visiting. In any of these cases, your browser is telling you the connection is not secure and you should not send sensitive information to that site.

Why websites use TLS certificates today

Websites use TLS certificates because browsers now treat them as a requirement for safety. Google Chrome, Firefox, Safari, and Edge all display a "Not Secure" warning on websites without a valid TLS certificate. Many users see that warning and leave immediately, so website owners install certificates to avoid losing visitors.

Search engines also rank websites with TLS certificates higher in search results than sites without them. Google has stated that HTTPS (the secure version of the web protocol that uses TLS) is a ranking factor, meaning a site without a certificate may appear lower in search results than a competitor with one.

The cost of TLS certificates has also dropped significantly. Let's Encrypt, a nonprofit certificate authority, offers free TLS certificates to any website owner. Many web hosting companies include a free certificate with their hosting plans. Because certificates are now free or very cheap and easy to install, there is no longer a good reason for a website to go without one.

The difference between HTTP and HTTPS

HTTP is the original protocol for transferring web pages from a server to your browser. HTTPS is HTTP with a TLS certificate and encryption added on top. The only difference you see is the "S" at the end of the protocol name in the address bar — http://example.com versus https://example.com — but that "S" means your connection is encrypted and verified.

Websites that handle sensitive information — banks, email providers, shopping sites, social media platforms — must use HTTPS. Websites that only display public information, like a news article or a blog post, can technically work without HTTPS, but most do not because of the browser warnings and search engine penalties. Today, the vast majority of websites use HTTPS.

Common questions about TLS certificates

A TLS certificate does not protect you from malware, phishing emails, or fake websites that have their own valid certificate. The certificate only proves that the website you are visiting is who it claims to be and that your connection to that website is encrypted. If a criminal registers a domain name that looks similar to a real bank's domain and obtains a valid certificate for it, your browser will show a padlock because the certificate is legitimate — it just belongs to the criminal's fake site. Always type the correct web address or use a bookmark rather than clicking links in emails.

A TLS certificate also does not protect information once it reaches the website's server. The encryption only covers the journey from your browser to the server. What the website does with your information after that — how securely they store it, whether they share it with others — is a separate security question. A padlock means the connection is safe, not that the website is trustworthy.

Frequently Asked Questions

What does it mean if my browser shows a warning about the certificate?

A certificate warning usually means the certificate has expired, the domain name in the certificate does not match the website you are visiting, or the certificate was issued by an authority your browser does not recognize. Do not enter passwords or payment information on a site showing a certificate warning. If it is a website you trust, contact the website owner to let them know their certificate needs attention.

Can I get a TLS certificate for free?

Yes. Let's Encrypt offers free TLS certificates to any website owner. Many web hosting companies also include a free certificate with their hosting plans. The free certificates work exactly the same way as paid ones — they encrypt your connection and verify the website's identity. The main difference is that free certificates expire after 90 days and must be renewed, though most hosting companies automate this renewal.

Why does a website need a TLS certificate if it does not handle payment information?

Even if a website does not handle payments, a TLS certificate protects login credentials, personal information, and any data you send through forms. It also prevents your internet service provider or network administrator from seeing what pages you visit on that site. Browsers now treat HTTPS as a standard expectation, so websites without certificates appear unsafe to visitors and rank lower in search results.

What happens if a TLS certificate expires?

If a certificate expires and is not renewed, browsers will show a warning that the website is unsafe and may block the page entirely. Website owners receive reminders before expiration and can renew the certificate in minutes. If you encounter an expired certificate warning on a website you trust, the website owner likely forgot to renew it — contact them to report the issue.

Can someone steal my password even with a TLS certificate?

A TLS certificate protects your password while it travels between your browser and the website's server, but it does not protect against phishing (fake websites that look real) or malware on your computer. Always verify you are on the correct website before entering a password, use unique passwords for important accounts, and keep your computer's security software up to date.