A Certification Authority is the organization that confirms a website is actually run by who it claims to be
When you visit a website and see a padlock icon in your browser's address bar, a Certification Authority (CA) is what made that padlock appear. The CA checked the website owner's identity, verified they control the domain, and issued a digital certificate that proves the connection between you and that website is encrypted and legitimate. Without this verification step, your browser has no way to know whether you are talking to the real bank website or a fake one designed to steal your password.
The CA does not host the website or manage your account. It simply acts as a trusted third party that says: "I checked this organization's paperwork, I confirmed they own this domain, and I am willing to put my reputation behind the claim that this certificate belongs to them." Your browser trusts the CA, so it trusts the certificate, so it trusts the website.
Key Takeaways
- A Certification Authority verifies that a website owner is who they claim to be before issuing a digital certificate that encrypts your connection.
- The padlock icon in your browser means a CA has confirmed the website's identity; without it, the site could be a fake designed to steal your information.
- Major CAs include DigiCert, Sectigo, and GlobalSign, and your browser comes pre-loaded with a list of CAs it trusts.
- If a CA issues a certificate to the wrong person or a certificate is compromised, your browser may show a security warning or block the site entirely.
- You cannot see which CA issued a certificate by looking at the padlock alone, but you can click the padlock to view the certificate details.
How a Certification Authority verifies a website owner
When a website owner wants to secure their site, they contact a Certification Authority and request a certificate. The CA then performs checks to confirm the owner's identity and domain ownership. The level of checking depends on the type of certificate requested.
For a basic Domain Validated (DV) certificate, the CA confirms only that the applicant controls the domain—usually by sending an email to an address listed in the domain's public records, or by asking the applicant to add a specific text file to the website. This takes hours to days and is the cheapest option.
For an Organization Validated (OV) certificate, the CA also verifies the business exists, checks business registration records, and may call the business phone number to confirm. This takes days to weeks and costs more.
For an Extended Validation (EV) certificate, the CA performs the most thorough checks: verifying the business is registered, checking legal documents, confirming the applicant has authority to request the certificate, and sometimes conducting a site visit. These certificates used to trigger a green address bar in older browsers, though most modern browsers no longer display this distinction prominently.
Which organizations act as Certification Authorities
Hundreds of CAs exist worldwide, but a small number issue the vast majority of certificates. DigiCert, Sectigo, GlobalSign, GoDaddy, and Let's Encrypt are among the largest. Your browser comes pre-loaded with a list of CAs it trusts—usually 50 to 100 of them—and it will only trust certificates issued by CAs on that list.
Let's Encrypt is unusual because it is a nonprofit that issues free certificates and automates the entire process. Most other CAs charge annual fees ranging from under $10 to several hundred dollars depending on the certificate type and the CA's brand reputation.
Each CA maintains its own security practices and policies. If a CA is compromised or issues a certificate to the wrong person, it damages the CA's reputation and can lead browsers to stop trusting that CA's certificates. This has happened: in 2011, a Dutch CA called DigiNotar was hacked and issued fraudulent certificates, and browsers eventually stopped trusting it entirely.
What happens when you visit a website with a CA-issued certificate
When your browser connects to a website, the website sends its certificate to your browser. Your browser then checks: Does this certificate come from a CA I trust? Has the certificate expired? Does the domain name in the certificate match the domain I am trying to visit? If all three answers are yes, the browser shows the padlock and establishes an encrypted connection.
If any check fails, your browser shows a warning. If the certificate was issued by a CA your browser does not trust, you will see "Your connection is not private" or similar language, and the browser will block you from visiting the site unless you explicitly override the warning. If the domain name in the certificate does not match the website you are visiting, the browser will also block the connection—this is one way to catch fake websites that have stolen a legitimate certificate.
If the certificate has expired, the browser warns you that the website owner has not renewed their certificate. This does not necessarily mean the site is malicious, but it does mean the owner is not maintaining their security, which is a red flag.
How to check which Certification Authority issued a certificate
Click the padlock icon in your browser's address bar. Most browsers will show a small popup or panel with basic security information. Look for a link or button that says "Certificate" or "Connection is secure" or "Details"—the exact wording varies by browser. Click it to open the full certificate details.
In the certificate details, you will see a field labeled "Issued by" or "Issuer." This field names the Certification Authority. You will also see the certificate's expiration date, the domain it covers, and the type of validation (DV, OV, or EV if applicable).
If you see a CA name you do not recognize, that is usually fine—most CAs are legitimate even if they are not household names. If you see a warning that the certificate is not trusted, or if the domain name does not match the website you are visiting, do not enter any passwords or personal information on that site.
Why Certification Authorities matter for your security
A Certification Authority is your assurance that the website you are visiting is not an imposter. Without CAs, a criminal could register a domain that looks like your bank's website, host it on their own server, and you would have no way to know the difference. The padlock would not appear, but many people do not notice the padlock or do not know what it means.
CAs are not perfect. A CA can make mistakes, a CA can be hacked, or a CA can issue a certificate to someone who lies on their application. But CAs have financial incentive and legal liability to get it right, because if they issue bad certificates, browsers stop trusting them and their business collapses. This creates a system of checks that is far from foolproof but much better than no verification at all.
The padlock is not a may provide that a website is safe or that the organization behind it is trustworthy. It only means the website's identity has been verified by a CA and the connection is encrypted. A legitimate business can still run a scam, and a hacked legitimate website can still steal your data. But the padlock does mean you are talking to the real website, not a fake one.
What to do if you see a certificate warning
If your browser shows a security warning about a certificate, stop and read the warning carefully. The most common reasons are: the certificate has expired (the website owner forgot to renew it), the domain name does not match (you may be on a fake site), or the CA is not trusted (rare, but possible).
If you are trying to visit a website you trust and you see a warning, contact the website owner through a phone number or email address you find independently—not through the website itself. Tell them their certificate has expired or is invalid. Do not enter any passwords or sensitive information until the certificate issue is resolved.
If you are visiting a website for the first time and you see a warning, assume it is not safe and leave. The risk of entering your information is not worth the small chance that the warning is a false alarm.
Frequently Asked Questions
Can I trust a website if it has a padlock but I have never heard of the Certification Authority?
Yes. Most CAs are legitimate even if they are not famous. The padlock means a CA verified the domain owner's identity and issued a certificate. What matters is whether your browser trusts the CA, not whether you have heard of it. If your browser shows the padlock without a warning, the CA is on your browser's trusted list.
What does it mean if a website has no padlock?
It means the website either has no certificate or has a certificate that your browser does not trust. This does not automatically mean the site is malicious, but it does mean the website's identity has not been verified by a CA. Do not enter passwords or payment information on unencrypted sites.
If a website has a valid certificate, is it definitely safe?
No. A valid certificate means the website's identity is verified and the connection is encrypted, but it does not mean the website is run by honest people or that it is free from security flaws. A legitimate business can still run a scam, and a hacked legitimate website can still steal your data. The padlock is one layer of security, not a complete may provide.
Who decides which Certification Authorities my browser trusts?
Your browser's maker—Google, Mozilla, Apple, or Microsoft—maintains the list of trusted CAs. They add and remove CAs based on security audits and incidents. If a CA is compromised or behaves badly, the browser maker can remove it from the trusted list, and certificates from that CA will no longer work.
Can a Certification Authority see my passwords or personal information?
No. The CA issues the certificate that encrypts your connection, but the CA does not see the data flowing through that connection. Only the website you are visiting can see your passwords and personal information. The CA's role ends once the certificate is issued.