A digital certificate is a file that proves who you are online
A digital certificate is a block of data that your web browser or email program uses to verify that a website or person is actually who they claim to be. It works like an ID card for the internet — it contains your name (or a website's name), a public key that encrypts data, and a digital signature from a trusted authority that says "I checked, and this is real."
When you visit a website with a digital certificate, your browser checks that certificate before you send any passwords or payment information. If the certificate is valid, you see a padlock icon in the address bar. If something is wrong — the certificate expired, or it belongs to a different website — your browser warns you before you proceed.
Digital certificates are also used in email to prove that a message really came from the person who signed it, and to encrypt messages so only the intended recipient can read them. They are the foundation of how encryption actually works in practice.
Key Takeaways
- A digital certificate contains a website's or person's name, a public encryption key, and a signature from a trusted authority that verifies the identity.
- Your browser automatically checks certificates when you visit websites and warns you if something is wrong or missing.
- The padlock icon in your address bar means the website has a valid certificate and your connection is encrypted.
- Digital certificates expire and must be renewed, which is why some websites occasionally show certificate warnings.
- Email certificates let you encrypt messages and digitally sign them so recipients know the message came from you.
How a digital certificate proves identity
A digital certificate contains several pieces of information. The most important are the owner's name (or domain name for websites), the owner's public key, the issue date and expiration date, and a digital signature from a certificate authority — an organization trusted to verify identities.
When you connect to a website, your browser receives the certificate and checks the signature. The signature is created using the certificate authority's private key, which only that authority has. Your browser has a list of trusted certificate authorities built in, so it can verify that the signature is real. If the signature is valid, the browser knows the certificate authority checked the identity and approved it.
This chain of trust is what makes the system work. You trust your browser, your browser trusts certain certificate authorities, and those authorities have verified the website's identity. If any link in that chain breaks — the certificate is fake, expired, or issued to the wrong domain — your browser stops you and shows a warning.
What happens when you visit a website with a certificate
When your browser connects to a website that has a digital certificate, several things happen automatically. First, the website sends its certificate to your browser. Your browser checks whether the certificate authority that signed it is in the browser's list of trusted authorities.
Next, your browser verifies that the certificate has not expired and that the domain name in the certificate matches the website you are visiting. If you are visiting example.com but the certificate says it belongs to different-site.com, your browser will show a warning even if the certificate is otherwise valid.
If all checks pass, your browser displays a padlock icon next to the website address. This tells you that the connection is encrypted and the website's identity has been verified. You can click the padlock to see details about the certificate, including who issued it and when it expires.
Why websites need digital certificates
Without digital certificates, a criminal could create a fake website that looks exactly like your bank's website and trick you into entering your login information. The fake site would have the same layout, colors, and text — but it would not have a valid certificate.
Digital certificates prevent this by proving that the website you are visiting is actually operated by the organization it claims to be. When you see the padlock icon, you know you are talking to the real website, not a copy. This is especially important for banking, shopping, email, and any site where you enter sensitive information.
Websites get certificates from certificate authorities like DigiCert, Sectigo, or Let's Encrypt. The certificate authority verifies the website owner's identity before issuing the certificate. For high-security sites like banks, the verification is thorough. For other sites, it may be simpler, but the certificate authority still checks that the person requesting the certificate controls the domain.
Digital certificates for email and documents
Digital certificates are not just for websites. You can also get a certificate for your email address to sign and encrypt messages. When you digitally sign an email, you are using your private key to create a signature that proves the message came from you and has not been changed since you sent it.
The recipient can verify your signature using your public key, which is stored in your certificate. This is useful in business and legal settings where you need proof that a message is authentic. Some email programs, like Outlook and Thunderbird, support digital signatures and encryption.
Digital certificates are also used to sign documents and software. When you download a program, it may be signed with a certificate to prove it came from the real developer and has not been tampered with. If the signature is invalid or missing, your operating system may warn you before you run it.
Certificate expiration and renewal
Digital certificates do not last forever. A website's certificate typically expires after one year, though some last longer. When a certificate is about to expire, the website owner must request a new one from a certificate authority.
If a website's certificate expires and is not renewed, your browser will show a warning that says the certificate has expired. This does not necessarily mean the website is unsafe — it may just mean the owner forgot to renew it. However, you should be cautious because expired certificates are sometimes a sign of an abandoned or compromised site.
Most legitimate websites renew their certificates automatically before they expire. Some certificate authorities send reminders, and many website hosting services handle renewal automatically as part of their service.
Self-signed certificates and when they appear
Sometimes you will see a warning about a certificate that is "self-signed." This means the certificate was signed by the website owner themselves, not by a trusted certificate authority. Your browser does not recognize the signature because the owner is not in its list of trusted authorities.
Self-signed certificates are sometimes used on internal company networks or for testing. They provide encryption, so your data is still scrambled in transit, but your browser cannot verify the website's identity. You should be very cautious about entering sensitive information on a site with a self-signed certificate unless you are certain it is legitimate.
In rare cases, you may add a self-signed certificate to your browser's trusted list if you control the network or have verified the certificate through another method. This is common in corporate environments where IT departments issue internal certificates.
Frequently Asked Questions
What does the padlock icon mean?
The padlock icon means the website has a valid digital certificate issued by a trusted authority, and your connection to the site is encrypted. Your data is scrambled so only you and the website can read it. A padlock does not may provide the website is trustworthy overall — it only means the identity has been verified and the connection is secure.
Is a website without a certificate unsafe?
A website without a certificate, or with an invalid certificate, should be treated with caution. Your browser will warn you before you connect. The site may be unsafe because you cannot verify who operates it, or it may simply be an old site that has not been updated. Do not enter passwords, payment information, or personal data on such sites.
Can I trust a website just because it has a certificate?
A valid certificate proves the website's identity and that your connection is encrypted, but it does not may provide the site is honest or safe from scams. A scammer can obtain a legitimate certificate for a fake site. Always check the domain name carefully, look for other signs of legitimacy, and be skeptical of unsolicited links.
What happens if a certificate is revoked?
If a certificate authority discovers that a certificate was issued by mistake or the private key was compromised, it can revoke the certificate. Your browser checks a revocation list to see if a certificate has been revoked. If it has, your browser will show a warning even if the certificate has not expired yet.
Do I need to do anything to use digital certificates?
No. Your browser handles digital certificates automatically when you visit websites. You do not need to install anything or take any action. If you want to sign or encrypt email, you would need to obtain an email certificate and configure your email program, but that is optional for most users.