A security certificate proves a website is who it claims to be

A security certificate is a digital document that a website uses to prove its identity and encrypt the information you send to it. When you visit a website with a certificate, your browser checks that the certificate is real, that it belongs to that website, and that it has not expired. If all three are true, your browser shows a padlock icon next to the web address and lets you know the connection is secure.

Without a certificate, anyone could set up a fake website that looks identical to your bank or email provider, and you would have no way to know the difference. A certificate prevents that by requiring a third party — called a certificate authority — to verify the website owner's identity before issuing the certificate. The certificate authority checks government records, business registration, or domain ownership before saying "yes, this is really who they claim to be."

The certificate also encrypts your data. When you type your password or credit card number into a website with a certificate, that data is scrambled so that only the website you intended to reach can read it. Without encryption, anyone on your network — at a coffee shop, airport, or even your own home network — could intercept what you type.

Key Takeaways

  • A security certificate proves a website's identity and encrypts the data you send, shown by a padlock icon in your browser's address bar.
  • Certificate authorities are independent organizations that verify a website owner's identity before issuing a certificate, preventing fake websites from impersonating real ones.
  • Certificates expire and must be renewed, so an expired certificate means the website owner has not maintained their security — a sign to be cautious.
  • Your browser automatically checks certificates; you do not need to do anything, but you should look for the padlock icon before entering passwords or payment information.
  • A missing certificate does not always mean a website is dangerous, but it does mean your data is not encrypted and the website's identity is not verified.

How to spot a secure website in your browser

Look at the address bar at the top of your browser. If the web address starts with https:// (not just http://), and there is a padlock icon to the left of the address, the website has a valid security certificate. The padlock means your browser has checked the certificate and confirmed it is real and current.

On most browsers, you can click the padlock to see details about the certificate. This shows you the name of the website the certificate belongs to, the certificate authority that issued it, and when it expires. If the certificate belongs to a different website than the one you are visiting, your browser will usually show a warning or block the page entirely.

If you do not see a padlock or the address starts with http:// (without the "s"), the website does not have a certificate. This does not automatically mean the website is fake or dangerous — many small websites and informational pages do not use certificates because they do not collect sensitive information. But you should never enter a password, credit card number, or other personal information on a website without a certificate.

Who issues security certificates and how they work

A certificate authority is an organization trusted by your browser to issue and verify security certificates. Major certificate authorities include DigiCert, Let's Encrypt, Sectigo, and GlobalSign. Your browser comes with a built-in list of certificate authorities it trusts, so when you visit a website, your browser checks whether the certificate was issued by one of those trusted authorities.

When a website owner wants a certificate, they contact a certificate authority and provide proof of their identity. For a small website, this might mean proving they own the domain name. For a business or bank, it means providing government-issued ID, business registration documents, or other official records. The certificate authority verifies this information, then issues a certificate that says "we have checked this person's identity and they own this website."

The certificate contains a pair of mathematical keys — one public and one private. The public key is shared with your browser, and the private key stays secret on the website's server. When you send information to the website, your browser uses the public key to encrypt it, and only the private key can decrypt it. This means even if someone intercepts your data, they cannot read it without the private key.

What happens when a certificate expires or is invalid

Security certificates have an expiration date, usually one to three years from when they are issued. When a certificate expires, the website owner must renew it with the certificate authority. If they do not, your browser will show a warning that the certificate has expired and ask whether you want to continue to the website.

An expired certificate does not mean the website is fake or hacked — it usually just means the owner forgot to renew it or has not maintained the site. But it is a sign that the website may not be actively managed, which is worth considering before you enter sensitive information. Many legitimate websites let their certificates lapse by accident and renew them as soon as they notice.

A certificate can also become invalid if it was issued to a different website. For example, if you visit example.com but the certificate says it belongs to fake-example.com, your browser will show a warning. This is one way your browser protects you from fake websites that look like the real thing but have a slightly different address.

The difference between standard and extended validation certificates

Most websites use a standard certificate, which proves the website owns the domain name and encrypts your data. A standard certificate takes a few minutes to issue once the certificate authority confirms you own the domain.

Some websites, especially banks and payment processors, use an extended validation certificate. This requires the certificate authority to do a more thorough background check — verifying the business exists, checking government records, and sometimes calling the business directly. Extended validation certificates take longer to issue but provide stronger proof of identity. In older browsers, extended validation certificates would display the company name in green next to the padlock, though most modern browsers no longer show this distinction.

For everyday browsing, a standard certificate provides the security you need. Extended validation is mainly useful when you are dealing with high-value transactions or sensitive financial information, and you want extra assurance the website is legitimate.

Why your browser trusts certain certificate authorities

Your browser comes with a built-in list of certificate authorities it trusts. These are organizations that have been vetted by browser makers like Google, Apple, and Mozilla. To stay on the trusted list, a certificate authority must follow strict rules about how they verify identities and issue certificates.

If a certificate authority issues a certificate to someone who does not own the website, or if they are hacked and someone steals their signing key, the browser maker can remove them from the trusted list. This has happened before — in 2011, a certificate authority was hacked and issued fake certificates for Google and other major websites. Once the browser makers found out, they removed that authority from their trusted lists, and the fake certificates stopped working.

This system is not perfect, but it makes it much harder for someone to create a convincing fake website. They would need to either steal a certificate authority's private key or trick a certificate authority into issuing them a certificate for a website they do not own — both of which are difficult and leave a trail.

What to do if you see a certificate warning

If your browser shows a warning about a certificate, stop and read it carefully. Common warnings include "This certificate has expired," "This certificate is not trusted," or "The certificate does not match the website address." These warnings exist to protect you, and you should take them seriously.

If you are visiting a website you trust and you see a warning, the most likely explanation is that the website owner has not renewed their certificate or has misconfigured it. You can contact the website owner to let them know. Do not enter passwords, credit card numbers, or other sensitive information while the warning is showing.

If you are visiting a website you do not recognize and you see a certificate warning, leave the website. This is often a sign of a fake or compromised site. Your browser is warning you for a reason.

Frequently Asked Questions

Can a website be safe without a security certificate?

A website without a certificate can still be legitimate, but your data is not encrypted when you send it. You should never enter passwords or payment information on a website without a certificate. For reading articles or browsing information, it is usually fine.

If a website has a certificate, does that mean it is definitely safe?

A certificate proves the website's identity and encrypts your data, but it does not may provide the website is honest or free from malware. A scam website can have a valid certificate. Always check the website address carefully and use common sense — if something seems suspicious, it probably is.

Why do some websites show a green padlock and others show a gray one?

Modern browsers show the same padlock for all valid certificates. Older browsers used to show a green padlock for extended validation certificates and a gray one for standard certificates, but most browsers have stopped doing this because it did not actually make users safer.

What does "mixed content" mean when my browser warns about it?

Mixed content means the website has a certificate, but some of the images, scripts, or other files on the page are loaded from websites without certificates. Your browser warns you because those unencrypted files could be intercepted. The page is still mostly secure, but not completely.

Do I need to buy a certificate for my own website?

If you run a website that collects any information from visitors — passwords, email addresses, payment information — you should have a certificate. Let's Encrypt offers free certificates for most websites. If your website is just informational and does not collect data, a certificate is not required but is still a good idea.