A Certificate Authority is the organization that confirms a website is actually who it claims to be
When you visit a website and see a padlock icon in your browser, a Certificate Authority (CA) is what made that padlock appear. The CA checked that the website owner really owns the domain name, then issued a digital certificate proving it. Without that certificate, your browser would show a warning instead of the padlock, and you would have no way to know if you were talking to the real website or an imposter.
Think of a CA the way you think of a government ID office. Just as an ID office verifies your identity before issuing a driver's license, a CA verifies a website's identity before issuing a certificate. The certificate is a digital document that says "I checked this website, and it really is example.com." Your browser trusts the CA, so it trusts the certificate, so it trusts the website.
The certificate does two things at once. First, it proves the website is who it says it is — this stops criminals from setting up fake websites that look identical to the real ones. Second, it encrypts the data traveling between your browser and the website, so no one listening in on your internet connection can read your passwords or credit card numbers.
Key Takeaways
- A Certificate Authority verifies that a website owner actually owns the domain name before issuing a certificate that proves it.
- Your browser comes pre-loaded with a list of CAs it trusts, so when a website shows a certificate from one of those CAs, your browser knows the site is legitimate.
- If a website has no certificate or a certificate from an untrusted CA, your browser will show a warning instead of a padlock icon.
- The certificate also encrypts your connection to the website, so your passwords and payment information cannot be read by someone on your network.
How a Certificate Authority checks a website's identity
When a website owner wants a certificate, they contact a CA and ask for one. The CA then verifies that the person asking actually owns or controls the domain name. The verification method depends on how strict the CA wants to be.
For a basic certificate, the CA might send an email to the domain owner's registered email address and ask them to click a link. This proves the person asking has access to that email account. For a stronger certificate, the CA might require documents like a business license or a phone call to a listed business number. The most rigorous certificates require in-person verification or a visit from a CA representative.
Once the CA is satisfied, it creates a certificate containing the domain name, the website owner's public key (used for encryption), and the CA's digital signature. The CA's signature is what makes the certificate trustworthy — it proves the CA actually checked and approved it. If a criminal tried to forge a certificate, they would not have the CA's private key, so their forgery would not have a valid signature.
Why your browser trusts certain Certificate Authorities
Your browser comes with a built-in list of CAs it trusts. This list includes companies like DigiCert, Let's Encrypt, Sectigo, and GlobalSign. When you visit a website, your browser checks whether the certificate was signed by one of these trusted CAs. If it was, the browser shows the padlock. If it was not, the browser shows a warning.
Getting on this trusted list is difficult. A CA must prove it follows strict security practices, keeps its private keys safe, and verifies website owners carefully. If a CA makes a mistake and issues a certificate to the wrong person, it can lose its trusted status. This happened to Symantec in 2017 — it issued certificates without proper verification, and Google and Mozilla removed it from their trusted lists.
Different browsers maintain different lists, though they overlap significantly. Chrome, Firefox, Safari, and Edge all have their own root certificate stores. A website might have a certificate trusted by Chrome but not by an older browser, which is why some websites show warnings in older versions of Internet Explorer.
What happens when a website does not have a valid certificate
If you visit a website with no certificate or an expired certificate, your browser will show a warning before letting you proceed. The warning usually says something like "Your connection is not private" or "This site's security certificate is not trusted." You can usually click through the warning, but you should not enter any sensitive information on that website.
A missing or invalid certificate does not always mean the website is malicious — it might just mean the owner forgot to renew it or has not set it up yet. But it does mean you have no proof the website is who it claims to be. A criminal could have set up an identical-looking fake website, and without a certificate, you would have no way to tell the difference.
Some websites intentionally use self-signed certificates, which means the owner signed the certificate themselves instead of having a CA sign it. These certificates still encrypt your connection, but your browser will not trust them because they were not signed by a CA on the trusted list. Self-signed certificates are common on internal company networks or for testing, but they should never appear on a public website you are paying money to.
The difference between Certificate Authorities and encryption
A Certificate Authority and encryption are related but separate. The CA verifies identity — it proves the website is who it says it is. Encryption scrambles your data so no one can read it. A website can have encryption without a CA certificate (using a self-signed certificate), but then you would have no proof of the website's identity.
The certificate contains the website's public key, which is used to start the encryption process. When your browser connects to a website, it uses the public key from the certificate to set up an encrypted connection. This is why a valid certificate is important — if you are encrypting to the wrong website, the encryption does not help you.
Types of certificates and what they verify
Not all certificates verify the same level of identity. A Domain Validation (DV) certificate only proves someone controls the email address or domain name — it does not verify the business behind it. These are fast and cheap, which is why Let's Encrypt issues them for free. A Organization Validation (OV) certificate requires the CA to verify the business actually exists and is registered. A Extended Validation (EV) certificate requires the most verification — the CA checks business documents, calls the business phone number, and sometimes visits in person. EV certificates used to show a green bar in the browser, though most browsers have removed this feature.
For most websites, a DV certificate is enough. For banks, payment processors, and other sites handling sensitive information, an OV or EV certificate is more appropriate. The difference is not in the encryption strength — all three encrypt equally well. The difference is in how much identity verification the CA performed before issuing the certificate.
How to check a website's certificate
You can see a website's certificate by clicking the padlock icon in your browser's address bar. In Chrome, click the padlock and then click "Certificate is valid." In Firefox, click the padlock, click the arrow next to "Connection secure," and then click "More information." This opens a window showing the certificate details, including the domain name it covers, the CA that issued it, and when it expires.
Look for the issuer name — it should be one of the well-known CAs like DigiCert, Let's Encrypt, or Sectigo. If the issuer is unknown or the certificate is self-signed, be cautious. Also check the expiration date — an expired certificate means the website owner did not renew it, which is a sign of poor maintenance. A website with an expired certificate might be abandoned or neglected.
Frequently Asked Questions
Can a Certificate Authority issue a certificate for any website?
No. A CA must verify that the person asking actually owns or controls the domain name. If someone tries to get a certificate for google.com without owning google.com, the CA will reject the request. This verification is what stops criminals from creating fake versions of popular websites.
What does it mean if my browser shows a certificate warning?
It means the certificate is missing, expired, or issued by a CA your browser does not trust. Do not enter passwords or payment information on that website. The website owner needs to fix the certificate before it is safe to use.
If a website has a certificate, is it definitely safe?
A valid certificate proves the website is who it claims to be and encrypts your connection. But it does not prove the website is honest or that the business behind it is legitimate. A scam website can have a valid certificate if the scammer owns the domain name. Always check the website's reputation and business details separately.
Why do some websites use Let's Encrypt instead of paid CAs?
Let's Encrypt is a free CA that issues Domain Validation certificates. It is trusted by all major browsers and provides the same encryption as paid CAs. The main difference is that Let's Encrypt does less identity verification — it only confirms you control the domain name, not that your business is legitimate. For most websites, this is enough.
Can a Certificate Authority revoke a certificate?
Yes. If a CA discovers it issued a certificate by mistake, or if a website owner reports their private key was stolen, the CA can revoke the certificate. Your browser will then show a warning when you visit that website, even though the certificate technically still exists.