An SSL certificate encrypts the data you send to a website so that only the website can read it
When you visit a website with "https://" in the address bar instead of "http://", an SSL certificate is protecting your connection. SSL stands for Secure Sockets Layer. The certificate is a small file the website's owner installs on their server that tells your browser: "This is a real website, and I've proven my identity to a trusted authority." Your browser then creates an encrypted tunnel between you and that server. Anything you type — passwords, credit card numbers, search queries, form data — travels through that tunnel scrambled so that hackers watching your internet traffic cannot read it.
Without SSL, your data travels in plain text. A person on the same coffee shop WiFi network as you could intercept it. Your internet service provider could see it. A compromised router could log it. SSL does not make the website itself trustworthy or safe from malware, but it does make sure that what you send stays private between you and the server you intended to reach.
Key Takeaways
- An SSL certificate encrypts data between your browser and a website's server, so passwords and payment information cannot be read by others on the network.
- The "https://" in a website address and a padlock icon in your browser's address bar both signal that SSL is active.
- SSL certificates are issued by trusted third-party organizations called certificate authorities, which verify the website owner's identity before issuing the certificate.
- An expired or mismatched SSL certificate will trigger a browser warning, which means the encryption may not be working or the website may not be what it claims to be.
How SSL encryption actually works
SSL uses two types of encryption working together. First, your browser and the website exchange public keys — think of these as locks that anyone can see. Your browser uses the website's public key to scramble your data into a code that only the website's private key can unlock. The website does the same with data it sends back to you. This happens so fast you do not notice it, but it means that even if someone intercepts the encrypted data, they cannot read it without the private key, which stays on the website's server.
The second layer is the certificate itself. Before a website can use SSL, its owner must request a certificate from a certificate authority — an organization trusted by browsers like Chrome, Firefox, and Safari. The certificate authority verifies that the person requesting the certificate actually owns or controls the website. They then issue a certificate that your browser checks automatically. If the certificate is valid and matches the website address you are visiting, your browser shows the padlock icon and "https://" in the address bar. If something is wrong — the certificate expired, or it was issued for a different domain — your browser will show a warning.
What certificate authorities do and why they matter
A certificate authority is a company or organization that issues SSL certificates after verifying the website owner's identity. Major certificate authorities include DigiCert, Sectigo, GlobalSign, and Let's Encrypt. Your browser comes with a built-in list of certificate authorities it trusts. When you visit a website, your browser checks: "Is this certificate signed by one of the authorities I trust? Does the certificate match the website address I am visiting? Has the certificate expired?" If all three answers are yes, the connection is secure.
This system prevents a common attack called a man-in-the-middle attack. A hacker cannot simply create their own SSL certificate for your bank's website and trick your browser into trusting it, because your browser will reject any certificate that is not signed by a trusted authority. The certificate authority's job is to make sure that only the real owner of a website can get a certificate for that domain.
The difference between http and https
The only difference between "http://" and "https://" is the "s" — which stands for "secure." An http connection sends data in plain text. An https connection uses SSL to encrypt it. Most websites today use https, and major browsers like Chrome now show a warning when you visit an http site, especially if you are about to enter a password or payment information.
Some websites use http for pages where you are just reading content — a news article, for example — and switch to https only when you log in or make a purchase. This is acceptable because the unencrypted pages do not contain sensitive information. However, if you see an http address when you are about to enter a password or credit card number, that is a red flag. Leave the site and contact the business through a phone number or address you know is real to report the problem.
What happens when an SSL certificate expires or does not match
Every SSL certificate has an expiration date, usually one to three years from the date it was issued. When a certificate expires, the website owner must renew it with the certificate authority. If they do not, your browser will show a warning that says something like "Your connection is not private" or "This site's security certificate is not trusted." This does not always mean the website is malicious — it often just means the owner forgot to renew. But you should not enter passwords or payment information on a site with an expired certificate, because the encryption may not be working.
A certificate mismatch happens when the certificate was issued for a different domain than the one you are visiting. For example, if a certificate was issued for "example.com" but you are visiting "www.example.com" or "shop.example.com," your browser may show a warning. Some certificates cover multiple domains or use wildcards to cover subdomains, but if the certificate does not match, your browser will let you know. Again, this is usually a configuration error by the website owner, but it means you should not trust the connection until it is fixed.
Self-signed certificates and when you might see them
A self-signed certificate is one that a website owner creates and signs themselves, rather than having a certificate authority issue it. Your browser does not trust self-signed certificates by default, so it will show a warning. You might see self-signed certificates on internal company networks, testing servers, or small local services that are not meant for the public internet. If you are visiting a public website and see a self-signed certificate warning, that is a sign something is wrong — either the website owner is cutting corners on security, or you are not actually on the website you think you are.
Some people dismiss these warnings and click through anyway. That is risky. A self-signed certificate provides encryption, so your data is still scrambled, but it does not prove the website is who it claims to be. An attacker could create a self-signed certificate for a fake version of your bank's website and, if you are not careful, you could end up there.
How to check if a website's SSL certificate is valid
In most browsers, you can click the padlock icon next to the website address to see certificate details. In Chrome, click the padlock and then "Connection is secure" to see who issued the certificate, what domain it covers, and when it expires. In Firefox, click the padlock, then the arrow next to "Connection secure," then "More information" to see similar details. Safari shows a padlock but requires you to click "Show certificate" to see the full information.
You do not need to check this every time you visit a website — your browser does it automatically. But if you are suspicious about a site, or if your browser shows a warning, checking the certificate details can tell you whether the problem is a simple configuration error or a sign of something more serious. A certificate issued by a well-known certificate authority, matching the website address you are visiting, and not expired, means the encryption is working and the website owner has proven their identity to a trusted third party.
Frequently Asked Questions
Does an SSL certificate mean a website is safe from viruses or scams?
No. SSL only encrypts the connection between you and the website. It does not protect you from malware, phishing, or fraud. A scam website can have a valid SSL certificate. Always check the website address carefully, look for signs of legitimacy like contact information and a privacy policy, and be suspicious of unsolicited emails asking you to click links.
Can I use a website without SSL if I am not entering sensitive information?
Yes, but it is not ideal. If you are only reading public content, an unencrypted connection is less risky. However, anyone on your network can see what you are viewing. If you are on public WiFi, using a VPN is a better option than relying on http sites to keep your browsing private.
What does "certificate pinning" mean?
Certificate pinning is a security technique where an app or website tells your browser to accept only a specific certificate, not just any certificate from a trusted authority. Banks and other high-security services sometimes use it to prevent attackers from using a valid but fraudulent certificate to impersonate them. You do not need to do anything — it happens automatically.
Why do some websites show a warning even though they have https?
The most common reasons are an expired certificate, a certificate issued for a different domain, or a certificate from an authority your browser does not recognize. Less often, your computer's clock is set to the wrong date, which makes the browser think the certificate has expired. Check your system time, and if that is not the problem, avoid entering sensitive information on that site.
Do I need to buy an SSL certificate for my own website?
If you run a website, yes — you need an SSL certificate before visitors can connect securely. Many hosting providers include free certificates from Let's Encrypt, or you can purchase one from a certificate authority. The cost ranges from free to several hundred dollars per year depending on the type and provider.