Fundamentals

The padlock means almost nothing, and what to check instead

HTTPS proves a connection is private, not that the site at the other end is honest. The difference matters, and certificates can still tell you something.

"Look for the padlock" was good advice in 2010 and is close to useless now. It was never a statement about honesty, and today it is not even a statement about effort — a certificate takes ninety seconds and costs nothing.

What HTTPS actually promises

A padlock means two things, both narrow. Your connection to the server is encrypted, so nobody in between can read or alter what passes. And the server proved it controls the domain name in the address bar.

That is the whole promise. It says nothing about who owns the domain, whether the business is real, or whether your order will arrive. A fraudulent shop with a valid certificate has established an encrypted channel for taking your money.

Why it stopped being a signal

Certificates used to cost money and involve a human. Free automated issuance changed that, and rightly — encryption everywhere is a genuine gain and the web is better for it. But a control that everyone passes carries no information.

In this corpus a valid certificate is the norm across every band, including the worst. Presence proves nothing. Absence, on the other hand, is still meaningful: a shop asking for a card number without HTTPS today is either abandoned or indifferent, and neither is reassuring.

What certificates can still tell you

Not all certificates are the same, and the difference is in what was verified.

  • Domain validated. The issuer checked that whoever asked controls the domain. Automated, free, and the overwhelming majority. It says nothing about who they are.
  • Organisation validated. The issuer checked that a named legal entity exists and is connected to the domain. That takes paperwork.
  • Extended validation. A stricter version of the same idea, with a heavier identity check.

Browsers stopped showing this distinction, so it is invisible exactly where it would be most useful. A LegitSonar report shows it: the issuer and the validation level are both in the technical record, and the certificate criterion weighs them.

What to check instead

Replace "is there a padlock" with three questions that still discriminate: how old is the domain, is a real organisation named anywhere, and does the payment method let you reverse a mistake. Those survive the fact that security tooling has become free — which, for a fraudster, is the same as saying it has become available.

Keep reading

Other guides

Check a domain while it is fresh in your mind

Everything described here is what the scanner looks at. Point it at something and see the reasoning for yourself.

Analyse a domain