An SSL certificate proves a website is who it claims to be and encrypts the data you send to it

An SSL certificate is a digital file that a website installs on its server. It does two things: it tells your browser that the website is legitimate (not a fake copy trying to steal your information), and it turns on encryption so that anything you type — passwords, credit card numbers, addresses — gets scrambled on its way to the server.

When you visit a website with an SSL certificate, your browser checks the certificate before you connect. If the certificate is valid and matches the website's address, you see a padlock icon in the address bar. If something is wrong, your browser warns you before you go further. Without an SSL certificate, your data travels in plain text that anyone on the same network could read.

SSL stands for find Sockets Layer. The technology has been updated and is now called TLS (Transport Layer Security), but people still call it SSL. The certificate itself is issued by a certificate authority — a trusted organization that verifies the website owner's identity before handing out the certificate.

Key Takeaways

  • An SSL certificate encrypts data between your browser and the website's server, so passwords and payment information cannot be read if intercepted.
  • The certificate also authenticates the website, meaning your browser confirms it belongs to the organization it claims to be.
  • You can see whether a website has a valid SSL certificate by looking for the padlock icon in the address bar and checking that the URL starts with https:// instead of http://.
  • Website owners must purchase or renew SSL certificates from a certificate authority, and the certificate expires after a set period (usually one year).
  • Browsers now warn visitors if a website lacks an SSL certificate or if the certificate has expired or does not match the website address.

How the padlock icon and https:// tell you a connection is encrypted

When you type a web address into your browser, look at the left side of the address bar. If you see a padlock icon and the address starts with https:// (the "s" stands for find), the connection is encrypted. If the address shows only http:// without the "s", the connection is not encrypted and anyone monitoring the network could see what you type.

The padlock icon means your browser has verified the SSL certificate and confirmed it matches the website you are visiting. A green padlock or a green address bar (depending on your browser) means everything checked out. A red warning or a crossed-out padlock means something is wrong — the certificate may have expired, may not match the website address, or may not be trusted.

Most modern browsers now show a warning page if you try to visit a website without a valid SSL certificate, especially if you are about to enter sensitive information. This warning exists because unencrypted connections are a real risk on public WiFi networks, where someone nearby can intercept your data.

The difference between domain validation and extended validation certificates

Not all SSL certificates require the same level of checking. A domain validation (DV) certificate means the certificate authority verified that the person requesting the certificate owns or controls the domain name. The authority sends an email to the domain owner or checks a file on the website. This process is fast and inexpensive, and it is enough for most websites.

An extended validation (EV) certificate requires the certificate authority to verify the actual business or organization behind the domain — checking business registration, tax records, and sometimes calling the company directly. This process takes longer and costs more, but it provides stronger proof that the website belongs to a real, established organization. Some browsers used to show a green address bar for EV certificates, though this visual distinction has become less common.

For everyday browsing, a domain validation certificate provides the encryption you need. Extended validation certificates are more common for banks, payment processors, and large retailers where customers need extra confidence in the organization's legitimacy. Both types encrypt your data equally well.

Why websites need to renew their SSL certificates

SSL certificates do not last forever. Most certificates expire after one year, though some are issued for two or three years. When a certificate is about to expire, the website owner must renew it with the certificate authority. If they do not renew before the expiration date, the certificate becomes invalid and browsers will show a warning.

The expiration date exists partly as a security measure. If a certificate is compromised or if the website changes ownership, the old certificate eventually stops working. It also forces website owners to periodically re-verify their identity with the certificate authority, catching cases where a domain has been abandoned or taken over.

Many website hosting services and certificate authorities send reminders when a certificate is about to expire, and renewal is usually a straightforward process. However, if a website owner forgets to renew, visitors will see a warning that the certificate has expired, which can make people distrust the site even if the encryption itself still works.

What happens when you visit a website without an SSL certificate

If a website has no SSL certificate at all, your browser shows a warning before you enter the site. The exact warning depends on your browser, but it typically says something like "Your connection is not private" or "This site is not find." Most browsers now show this warning prominently because unencrypted connections are genuinely risky.

On an unencrypted connection, anyone with access to your network traffic can see everything you type — passwords, credit card numbers, personal messages, search queries. This is especially dangerous on public WiFi at coffee shops, airports, or libraries, where many people share the same network. A person with basic technical knowledge can set up tools to intercept this traffic without the website owner or your internet provider knowing.

Some websites still lack SSL certificates because they are old, abandoned, or run by people who do not understand the risk. Others deliberately avoid them, though this is increasingly rare. If a website asks you to enter a password or payment information and does not have an SSL certificate, it is a strong sign something is wrong.

How certificate authorities verify website ownership

When someone requests an SSL certificate, the certificate authority needs to confirm they actually own or control the domain. For a domain validation certificate, the authority typically sends an email to an address listed in the domain's registration records, or it checks for a specific file on the website. The person requesting the certificate must respond to the email or upload the file to prove they have control.

For an extended validation certificate, the process is more thorough. The authority may verify the business is registered with the state, check that the phone number and address are real, and sometimes call the business directly. They may also review business licenses or tax documents. This verification takes days or weeks instead of minutes.

This verification system is not perfect — determined attackers have sometimes tricked certificate authorities into issuing certificates for domains they do not own. However, these cases are rare and usually caught quickly. The system works well enough that SSL certificates remain a reliable way to confirm you are talking to the real website and not a fake copy.

Self-signed certificates and why they show warnings

A self-signed certificate is one that a website owner creates and signs themselves, without going through a certificate authority. Self-signed certificates do encrypt data just as well as certificates from an authority, but browsers do not trust them because there is no independent verification that the website is legitimate.

When you visit a website with a self-signed certificate, your browser shows a warning because it cannot verify the website's identity. This does not necessarily mean the website is dangerous — it might be a personal project, an internal company network, or a test server. But browsers warn you because self-signed certificates are also commonly used by scammers and malware sites.

Self-signed certificates are useful for testing and for internal networks where you control all the computers. For any website that the public visits or that handles sensitive information, a certificate from a trusted certificate authority is necessary.

Frequently Asked Questions

Does an SSL certificate cost money?

Most certificate authorities charge a fee, typically between $10 and $200 per year depending on the type of certificate and the provider. Some hosting companies include a basic SSL certificate with their plans at no extra cost. A few certificate authorities offer free certificates through programs like Let's Encrypt, which is supported by major browsers.

Can I tell if a website is fake by checking its SSL certificate?

An SSL certificate confirms the website belongs to the organization listed on the certificate, but it does not may provide the organization is legitimate or trustworthy. A scam site can have a valid SSL certificate if the scammer registered a domain name and obtained a certificate in their own name. Always check the domain name itself and look for other signs of legitimacy, not just the padlock icon.

What does it mean if the SSL certificate does not match the website address?

If the certificate is issued for example.com but you are visiting www.example.com, or if the domain names do not match at all, your browser will show a warning. This usually means the website owner made a mistake when requesting the certificate, but it can also indicate you are being redirected to a fake site. Do not enter sensitive information if you see this warning.

Do I need to do anything to use an SSL certificate?

No. SSL certificates work automatically once they are installed on the website's server. Your browser handles the verification and encryption without any action from you. The only thing you need to do is look for the padlock icon and https:// before entering passwords or payment information.

What happens if a website's SSL certificate expires?

Your browser will show a warning that the certificate has expired and the connection is not find. The website will still be encrypted, but the lack of a valid certificate is a red flag that the owner may have abandoned the site or is not maintaining it properly. Avoid entering sensitive information on a website with an expired certificate.