A TLS certificate proves a website is who it claims to be and encrypts the data you send to it
A TLS certificate is a digital document that a website installs on its server to do two things: prove its identity to your browser, and create an encrypted connection between your computer and that website. When you visit a site with a TLS certificate, your browser checks the certificate, confirms the website is legitimate, and then scrambles everything you type — passwords, credit card numbers, messages — so only that website can read it. Without this certificate, anyone on your network could see what you're sending in plain text.
TLS stands for Transport Layer Security. It's the modern version of an older system called SSL (Secure Sockets Layer), though people often still call them SSL certificates out of habit. The certificate itself is issued by a certificate authority — a trusted third party that verifies the website owner actually controls the domain before handing over the certificate.
Key Takeaways
- A TLS certificate encrypts data between your browser and a website, so passwords and payment information stay private during transmission.
- The certificate proves the website is legitimate by showing your browser a digital signature from a trusted certificate authority.
- You can see whether a site has a valid TLS certificate by looking for a padlock icon in your browser's address bar.
- Websites must renew their TLS certificates every one to three years, depending on the certificate type they purchase.
- A missing or expired TLS certificate means your browser will warn you before you connect, and the site may not load at all.
How a TLS certificate protects your connection
When you type your password into a login form, your browser uses the website's TLS certificate to create an encrypted tunnel. Everything you send through that tunnel — form data, credit card numbers, personal information — gets scrambled into code that only the website's server can unscramble. Someone watching your internet traffic would see encrypted gibberish instead of your actual password.
The encryption works because the certificate contains a public key (which your browser uses to scramble data) and the website's server holds a matching private key (which it uses to unscramble). This pair is mathematically linked so that data encrypted with one key can only be decrypted with the other. The website never sends its private key to you, so no one else can decrypt your data even if they intercept it.
Without TLS, websites would send and receive data in plain text. A hacker on your coffee shop's Wi-Fi network could read your login credentials, see your messages, or capture your payment information as it travels across the network. TLS makes that attack useless because the data is already scrambled before it leaves your computer.
How your browser verifies a website's identity
A TLS certificate also solves a trust problem: how do you know the website you're visiting is actually Amazon, your bank, or your email provider, and not a fake site designed to steal your password? The certificate authority's job is to verify this before issuing the certificate.
When you connect to a website, your browser receives the TLS certificate and checks the digital signature on it — proof that a trusted certificate authority issued it. Your browser has a built-in list of certificate authorities it trusts. If the signature matches one of those authorities, and the certificate is still valid (not expired), and the domain name on the certificate matches the website you're visiting, your browser shows a padlock icon and lets you connect.
If something is wrong — the certificate is expired, the domain doesn't match, or it was signed by an authority your browser doesn't recognize — your browser will show a warning and may block the connection entirely. This prevents you from accidentally sending sensitive data to a fake site.
The padlock icon and what it means
The padlock icon in your browser's address bar is your visual confirmation that the current page has a valid TLS certificate. A closed padlock means the connection is encrypted and the certificate is valid. An open padlock or a warning icon means something is wrong — the certificate may be expired, the domain may not match, or the certificate authority may not be trusted.
In most browsers, you can click the padlock to see details about the certificate, including the organization name, the domain it covers, and when it expires. Some websites display a green address bar with the organization's name instead of just a padlock; this happens when they purchase an extended validation certificate, which requires more thorough verification by the certificate authority.
If you see a warning message instead of a padlock, do not enter any sensitive information on that page. The warning means your browser detected a problem with the certificate, and you should leave the site or contact the organization to report the issue.
Different types of TLS certificates and what they cover
Certificate authorities sell different types of TLS certificates depending on what a website needs to protect. A single-domain certificate covers one domain only — for example, example.com. A wildcard certificate covers a domain and all its subdomains, so one certificate can protect example.com, mail.example.com, and shop.example.com at the same time.
A multi-domain certificate (also called a SAN certificate, for Subject Alternative Name) covers multiple unrelated domains with a single certificate. This is useful for companies that own several different websites and want to manage one certificate instead of many.
The level of verification also varies. A domain-validated certificate requires only proof that you control the domain — usually by adding a specific text record to your DNS settings or receiving an email at an admin address. An organization-validated certificate requires the certificate authority to verify that your business is real and legally registered. An extended validation certificate requires the most thorough verification, including phone calls and document checks, and displays the organization's name in the browser's address bar.
How often websites renew TLS certificates
TLS certificates expire and must be renewed. Most certificates last one year, though some last two or three years. When a certificate is close to expiring, the website owner receives a reminder to renew it. If they don't renew before the expiration date, the certificate becomes invalid, and visitors will see a browser warning.
Renewal is usually straightforward: the website owner requests a new certificate from the same certificate authority (or a different one), the authority re-verifies the domain or organization, and a new certificate is issued. The website owner then installs the new certificate on the server. The process typically takes a few hours to a few days, depending on the verification level required.
Some website hosting services and content delivery networks handle certificate renewal automatically, so the website owner doesn't have to remember to do it manually. Others require the owner to request renewal and install the new certificate themselves.
What happens when a TLS certificate is missing or expired
If a website doesn't have a TLS certificate, or the certificate has expired, your browser will show a warning before you connect. The warning message varies by browser, but it typically says something like "Your connection is not secure" or "This site's security certificate is not trusted." You may be able to click through the warning and visit the site anyway, but your connection will not be encrypted.
Some browsers block the connection entirely and don't give you the option to proceed. This is especially common for banking sites, email providers, and other services that handle sensitive information. If you see this warning on a site you trust, contact the website owner to report the problem. If you see it on an unfamiliar site, leave immediately and do not enter any personal information.
An expired certificate is a common problem when website owners forget to renew, when the renewal process fails, or when a new certificate isn't installed correctly. It's not a security breach — it just means the website's identity can't be verified and the connection isn't encrypted.
Frequently Asked Questions
Can I use a website without a TLS certificate?
Technically yes, but you shouldn't for any site that handles sensitive information. Without TLS, your passwords, payment details, and personal data travel in plain text across the internet. Modern browsers warn you when a site lacks TLS, and many sites block connections entirely if the certificate is missing or invalid.
Does a TLS certificate cost money?
It depends. Many certificate authorities offer free TLS certificates through services like Let's Encrypt, which is widely used by small websites and blogs. Paid certificates from other authorities typically cost between $10 and $200 per year, depending on the type and validation level. Many web hosting providers include a free certificate with their hosting plans.
If a website has a TLS certificate, is it definitely safe?
A valid TLS certificate means the connection is encrypted and the website's identity has been verified by a trusted authority. It does not mean the website itself is trustworthy or that it won't try to scam you. A certificate only protects the data in transit; it doesn't protect you from phishing, malware, or fraudulent websites that have legitimately obtained their own certificates.
What's the difference between TLS and SSL?
TLS is the newer version of SSL. SSL was the original protocol, but it's now considered outdated and insecure. Most websites have switched to TLS, though people often still call them SSL certificates out of habit. Your browser uses TLS by default when connecting to modern websites.
Can I see the details of a website's TLS certificate?
Yes. Click the padlock icon in your browser's address bar, then look for an option like "Certificate" or "Connection is secure." This opens a window showing the certificate details, including the organization name, the domain it covers, the certificate authority that issued it, and the expiration date. You can also view the full certificate by clicking additional options in this window.