What Is HTTPS and What Does the Padlock Guarantee?
Short answer
HTTPS is HTTP with encryption, so nobody between you and the website can read or alter what passes. The padlock means the connection is private and you are talking to the domain in the address bar. It says nothing about whether that site is trustworthy, and scam sites get the same padlock for free.
On this page
HTTPS is ordinary HTTP wrapped in encryption. The browser and the server agree on a shared secret at the start of the connection, and everything after that is scrambled in a way only those two can unscramble.
The padlock icon reports exactly one thing: that this wrapping is in place and that the certificate presented belongs to the domain shown in the address bar. It is widely read as a badge of legitimacy. It is not one, and the gap between those two readings is where a great deal of fraud lives.
What the encryption actually protects
Three properties, in the order they matter:
Confidentiality. Nobody between your device and the server can read the traffic. Not the café Wi-Fi, not other people on the network, not your internet provider, not the intermediate networks the traffic crosses.
Integrity. Nobody can alter it in transit. Before HTTPS was universal, some providers injected advertising into pages and some public hotspots rewrote links. That is not possible on an HTTPS connection without breaking it visibly.
Authentication of the domain. The certificate proves the server holds the
private key for example.com. A machine impersonating that domain cannot
produce a valid certificate for it.
That third point is precise and narrow. It proves you are connected to
example.com. It does not prove example.com deserves your trust.
What the padlock does not tell you
This is the part worth internalising.
| The padlock proves | The padlock says nothing about |
|---|---|
| The connection is encrypted | Whether the site is a scam |
| The certificate matches the domain | Who owns the domain |
| Nobody in between can read it | What the site does with your data |
| The page was not altered in transit | Whether the page content is true |
Certificates became free and automatic around 2016, which was the right outcome for the web, since universal encryption is better than encryption only for those who could pay. It also means a phishing site set up this morning has a valid certificate and a padlock within minutes.
So the padlock has become a baseline, like a building having a door. Its absence is informative; its presence tells you almost nothing.
Browsers have acknowledged this. Chrome replaced the padlock with a neutral tune icon specifically because research kept finding that users read the padlock as “this site is safe”. The icon changed because the belief was wrong.
Read the domain, not the icon
The useful check takes two seconds and it is the domain, not the padlock.
Find the first single slash in the URL. Everything before it is the host. The real domain is the last two labels of that host, read right to left.
https://hsbc.co.uk/personal→ domainhsbc.co.uk. Genuine.https://hsbc.co.uk.secure-id.net/login→ domainsecure-id.net. Phishing.https://www.hsbc-verify.com/→ domainhsbc-verify.com. Not the bank.
Anyone can register a domain containing any brand name, and anyone can create unlimited subdomains in front of it. Those two facts account for most phishing pages that people describe afterwards as “it had the padlock”.
Watch for lookalike characters too, because a Cyrillic “а” is visually
identical to a Latin “a” in most fonts. Browsers defend against this by
displaying suspicious internationalised domains in their raw xn-- form,
which looks like gibberish and should be treated as a warning.
What a certificate warning means
A full-page warning is different from a missing padlock, and should be treated seriously.
| Warning | Usual cause | Proceed? |
|---|---|---|
| Certificate expired | The site forgot to renew | Usually benign, still wait |
| Name mismatch | Wrong domain on the certificate | No |
| Issuer not trusted | Self-signed, or interception | No, unless you know why |
| Certificate revoked | Compromised key | No |
On a corporate laptop, a “not trusted” warning is often your employer’s traffic inspection, which is legitimate and deliberate and means they can read your HTTPS traffic. On a home network, the same warning is a genuine red flag. The mechanics of these certificates, and why expiry is the most common cause of all, are covered in how SSL and TLS certificates work.
Never click through a warning to enter a password. The one scenario the warning exists to prevent is exactly that.
What stays visible even with HTTPS
Encryption is not invisibility, and this is where expectations drift.
- The domain you are visiting is visible to your internet provider via DNS lookups and the connection handshake, unless you use encrypted DNS and the site supports Encrypted Client Hello.
- Your IP address is visible to the site, and the site’s address is visible to your provider.
- Traffic size and timing leak information. Which specific page on a site you loaded can sometimes be inferred from the pattern.
- Everything after decryption. The site itself sees everything you send it, in plain form. HTTPS protects the pipe, not the endpoint.
Realistic expectations
HTTPS is now the default across the web, and both Chrome and Firefox will warn before loading plain HTTP. Treat its presence as unremarkable and its absence as a reason to stop before typing anything.
The decision HTTPS cannot make for you is whether to trust the site. That rests on the domain being the one you meant, the site being one you sought out rather than one that contacted you, and — for anything involving money — reaching it through your own bookmark or app rather than a link in a message. Codes and links that arrive unprompted deserve the same scepticism, which is why QR codes get a padlock too without that meaning anything at all.