Skip to content
All termsTrust signals

SSL/TLS (the padlock symbol)

Encrypts the connection between browser and server. The padlock says nothing about the provider’s legitimacy.

What the padlock answers
QuestionAnswer of the padlock
Can someone read along?QuestionYes or noAnswer of the padlockNo, the connection is encrypted
Will I get my goods?QuestionYes or noAnswer of the padlockThe padlock says nothing about this
Who is behind the shop?QuestionName and companyAnswer of the padlockWith the simplest certificate (DV) only: the applicant controls the domain

The simplest certificate is free and issued in minutes. The large majority of websites use it, good and bad alike.

What encryption does

SSL (Secure Sockets Layer) and its successor TLS (Transport Layer Security) are encryption protocols that secure data transmission between browser and web server. You can recognise this by the “https” in the address and the padlock symbol in the browser. They prevent third parties from reading the transmitted data (e.g. entered payment details) while it is in transit.

SSL/TLS says something about the encryption of the connection and nothing about the identity, legitimacy or intent of the website operator behind it. Free, automated certificates (e.g. from Let’s Encrypt) are standard today and are used by reputable shops just as much as by fake shops. A padlock symbol therefore no longer sets reputable providers apart from others.

In practice, TLS protects above all against eavesdroppers on the transmission path, in an open Wi-Fi network in a café, a hotel or an airport, for example. Without encryption anyone on the same network could capture the address and card details you enter. That is what the technology was built for, and it does that job reliably. It was never meant to say anything about the honesty of the other side.

Browser warnings should therefore be taken seriously even when they look innocuous. An expired certificate, a certificate issued for a different domain, or a page loading part of its content unencrypted (“mixed content”) are substantive faults. With a shop you are about to entrust with your address and payment details, that is a good moment to abandon the process.

Levels of certificate validation

Technically there are three levels of scrutiny. A domain-validated certificate (DV) only confirms that the applicant controls the domain. That can be done fully automatically in minutes and costs nothing. An organisation-validated certificate (OV) additionally verifies that the company exists; an extended validation certificate (EV) verifies its identity as well. In practice the vast majority of all websites, good and bad alike, use the simplest level.

Earlier “Extended Validation” certificates with a visible company check in the browser now play virtually no role; modern browsers barely highlight them anymore. The browser display therefore no longer reveals how strictly a certificate was vetted. The difference between one issued automatically and one checked by hand has become invisible to visitors.

Checking the certificate yourself

A few clicks still yield usable clues. Click the padlock and look at the certificate details: which domain was it issued for, since when is it valid, and who issued it? A certificate that has only existed for a few days sits badly with a shop advertising many years of experience. In addition, all issued certificates are visible in public certificate transparency logs. There you can trace since when certificates have existed for a domain.

A check: click the padlock and compare the domain named in the certificate character by character with what stands in the address bar. On a rebuilt page the two will match, because the forgery lies in the domain name itself. This step therefore complements reading the address and does not replace it: only once the domain is the expected one does the certificate say anything useful.

A second clue is the issue date. A domain whose first certificate is only a few days old was until recently either not in operation at all or reachable without encryption. For a shop advertising many years of experience that is a contradiction which, unlike marketing copy, can be verified.

What the padlock proves

A typical abuse case shows why the padlock says nothing about trust: a phishing page on a typo domain, for instance with swapped letters or an extra word appended to the domain name, obtains a valid free certificate within minutes. The browser then shows the padlock, because the connection to that forged domain is correctly encrypted. Encrypted only means that nobody else can read along. Whether the page is trustworthy remains open.

The padlock answers the question “can anyone read along?” with no. It does not answer the question “will I get my goods?”. Anyone who confuses the two is treating as a quality mark a property that every operator can obtain for free in a matter of minutes.

An https padlock is a technical minimum feature. If it is missing altogether, that is a strong warning sign today: a shop without encryption transmits address and payment data in plain text and is not up to date. The padlock must therefore always be assessed together with the legal notice, payment methods, reviews and trust seals. It works as an exclusion criterion and does not work as proof of trust.

Check a specific shop

The shop check runs 39 check modules and explains every finding. No sign-up, no cost.