Guides Start here

SSL, HTTPS, and the padlock

What the padlock actually proves, what it does not, and why a site without one now actively warns your customers away.

4 min read No sales pitch

An SSL certificate encrypts the connection between your visitor and your website. That is the whole job. Everything else attached to it is marketing.

What it actually does

Without it, anything typed into your site travels in readable form across every network in between. With it, that traffic is scrambled. It matters most for forms and payments, but it now applies to every page.

Why every site needs one, even a brochure site

Browsers stopped treating this as optional years ago. A site without a certificate shows a "Not secure" warning in the address bar, and on some browsers an interstitial page before the visitor arrives. Search engines also treat HTTPS as a ranking signal.

So even if you collect nothing at all, the absence of a certificate costs you visitors who assume something is wrong.

What the padlock does not prove

It proves the connection is encrypted. It does not prove the business is legitimate, trustworthy, or who they say they are. Scam sites have padlocks too, because certificates are free and automatic.

What it should cost

Nothing. Free automated certificates have been standard since 2016 and every competent host issues and renews them without being asked.

Paid certificates exist and have real uses at the enterprise level, tied to warranties and organisational validation. A restaurant, villa, or charter operator does not need one. If your hosting bill has a line item for a basic certificate, ask about it.

Things to check

  • Every page loads over https, not just the checkout
  • The http version redirects to https rather than both existing
  • Renewal is automatic. Expired certificates are a common and entirely avoidable outage

Start here

Questions this did not answer?

Ask a plain one and get a plain answer. No budget, project, or vocabulary required.