Skip to main content
FixMyTech

What Is HTTPS and What Does the Padlock Guarantee?

By

Published

7 min read

Share

Short answer

HTTPS is HTTP with encryption, so nobody between you and the website can read or alter what passes. The padlock means the connection is private and you are talking to the domain in the address bar. It says nothing about whether that site is trustworthy, and scam sites get the same padlock for free.

On this page

HTTPS is ordinary HTTP wrapped in encryption. The browser and the server agree on a shared secret at the start of the connection, and everything after that is scrambled in a way only those two can unscramble.

The padlock icon reports exactly one thing: that this wrapping is in place and that the certificate presented belongs to the domain shown in the address bar. It is widely read as a badge of legitimacy. It is not one, and the gap between those two readings is where a great deal of fraud lives.

What the encryption actually protects

Three properties, in the order they matter:

Confidentiality. Nobody between your device and the server can read the traffic. Not the café Wi-Fi, not other people on the network, not your internet provider, not the intermediate networks the traffic crosses.

Integrity. Nobody can alter it in transit. Before HTTPS was universal, some providers injected advertising into pages and some public hotspots rewrote links. That is not possible on an HTTPS connection without breaking it visibly.

Authentication of the domain. The certificate proves the server holds the private key for example.com. A machine impersonating that domain cannot produce a valid certificate for it.

That third point is precise and narrow. It proves you are connected to example.com. It does not prove example.com deserves your trust.

What the padlock does not tell you

This is the part worth internalising.

The padlock proves The padlock says nothing about
The connection is encrypted Whether the site is a scam
The certificate matches the domain Who owns the domain
Nobody in between can read it What the site does with your data
The page was not altered in transit Whether the page content is true

Certificates became free and automatic around 2016, which was the right outcome for the web, since universal encryption is better than encryption only for those who could pay. It also means a phishing site set up this morning has a valid certificate and a padlock within minutes.

So the padlock has become a baseline, like a building having a door. Its absence is informative; its presence tells you almost nothing.

Browsers have acknowledged this. Chrome replaced the padlock with a neutral tune icon specifically because research kept finding that users read the padlock as “this site is safe”. The icon changed because the belief was wrong.

Read the domain, not the icon

The useful check takes two seconds and it is the domain, not the padlock.

Find the first single slash in the URL. Everything before it is the host. The real domain is the last two labels of that host, read right to left.

  • https://hsbc.co.uk/personal → domain hsbc.co.uk. Genuine.
  • https://hsbc.co.uk.secure-id.net/login → domain secure-id.net. Phishing.
  • https://www.hsbc-verify.com/ → domain hsbc-verify.com. Not the bank.

Anyone can register a domain containing any brand name, and anyone can create unlimited subdomains in front of it. Those two facts account for most phishing pages that people describe afterwards as “it had the padlock”.

Watch for lookalike characters too, because a Cyrillic “а” is visually identical to a Latin “a” in most fonts. Browsers defend against this by displaying suspicious internationalised domains in their raw xn-- form, which looks like gibberish and should be treated as a warning.

What a certificate warning means

A full-page warning is different from a missing padlock, and should be treated seriously.

Warning Usual cause Proceed?
Certificate expired The site forgot to renew Usually benign, still wait
Name mismatch Wrong domain on the certificate No
Issuer not trusted Self-signed, or interception No, unless you know why
Certificate revoked Compromised key No

On a corporate laptop, a “not trusted” warning is often your employer’s traffic inspection, which is legitimate and deliberate and means they can read your HTTPS traffic. On a home network, the same warning is a genuine red flag. The mechanics of these certificates, and why expiry is the most common cause of all, are covered in how SSL and TLS certificates work.

Never click through a warning to enter a password. The one scenario the warning exists to prevent is exactly that.

What stays visible even with HTTPS

Encryption is not invisibility, and this is where expectations drift.

  • The domain you are visiting is visible to your internet provider via DNS lookups and the connection handshake, unless you use encrypted DNS and the site supports Encrypted Client Hello.
  • Your IP address is visible to the site, and the site’s address is visible to your provider.
  • Traffic size and timing leak information. Which specific page on a site you loaded can sometimes be inferred from the pattern.
  • Everything after decryption. The site itself sees everything you send it, in plain form. HTTPS protects the pipe, not the endpoint.

Realistic expectations

HTTPS is now the default across the web, and both Chrome and Firefox will warn before loading plain HTTP. Treat its presence as unremarkable and its absence as a reason to stop before typing anything.

The decision HTTPS cannot make for you is whether to trust the site. That rests on the domain being the one you meant, the site being one you sought out rather than one that contacted you, and — for anything involving money — reaching it through your own bookmark or app rather than a link in a message. Codes and links that arrive unprompted deserve the same scepticism, which is why QR codes get a padlock too without that meaning anything at all.

Frequently asked questions

Can my internet provider see what I do on HTTPS sites?
They see which sites you visit, not what you do there. The domain name is visible through DNS and the connection handshake, so they can log that you connected to a bank. The pages, searches and form data inside are encrypted.
Is a site with a padlock safe to enter my card details on?
The padlock only tells you the connection is encrypted. Your card details will reach the site's owner unreadable by anyone in between, and what the owner does with them is a separate question the padlock does not answer.
Why do some sites still use plain HTTP?
Very few do now. Browsers mark them as "Not secure" and search engines rank them lower, so the remaining cases are mostly old internal tools, router admin pages and abandoned sites nobody has updated.
Does HTTPS slow down a website?
Not measurably on modern hardware. The initial handshake adds a few milliseconds, and HTTPS is a prerequisite for HTTP/2 and HTTP/3, which are faster than plain HTTP/1.1. The net effect on a modern site is usually a speed improvement.
What does the "Not secure" warning actually risk?
On plain HTTP, anyone on the same network or anywhere along the path can read every page you load and every form you submit, and can modify the page before it reaches you. The practical risk depends heavily on the network, and public Wi-Fi is far worse than home broadband.

All Explainers guides