It proves the connection is encrypted and the certificate matches the domain. It says nothing about whether the business is trustworthy, and every site needs one regardless because browsers now warn without it.

What it actually means

Two things, both narrow.

That traffic between the visitor's browser and the server is encrypted, so somebody on the same network cannot read it.

And that the certificate was issued for that domain, so the visitor is talking to the site whose address they typed rather than something impersonating it.

That is the whole guarantee. It is genuinely valuable and it is not what most people think it means.

What it does not mean

The third is worth dwelling on. Basic certificates are issued automatically to anybody who can demonstrate control of a domain, which takes minutes and costs nothing.

Which means a fraudulent site can display a padlock, and most of them do, because it is trivial to obtain and its absence is now a warning sign.

Why you need one anyway

The absence has become the signal rather than the presence.

Browsers now mark sites without a certificate as not secure, prominently, and warn before submitting a form.

A visitor seeing that on a contact page will frequently leave, because the warning is alarming and the explanation is not.

Search engines also treat it as a factor, and some functionality now requires it.

So the reasoning has inverted entirely. A certificate no longer marks you as careful; its absence marks you as neglected.

A worked example

A tradesman whose site had no certificate, on the reasoning that he took no payments and collected nothing sensitive.

Technically that was a fair assessment of the risk.

What he had not accounted for was the browser warning appearing beside his address, and a red notice when somebody clicked into the contact form.

Two customers mentioned it, one asking whether the site had been hacked.

Adding a certificate took twenty minutes through his host, at no cost, and removed the warnings entirely.

His enquiry rate improved noticeably over the following months, which he attributed to people no longer being warned off at the moment they tried to make contact.

The types, and which you need

Three exist and the differences matter less than certificate sellers suggest.

Domain validated confirms control of the domain. Issued automatically, free from several sources, and sufficient for almost every small business site.

Organisation validated involves some checking of the business. Costs money and produces no visible difference to a normal visitor.

Extended validation involves more checking. Browsers used to display the company name prominently for these and largely stopped, which removed most of the point.

For a brochure site or a small shop using a hosted payment provider, the free option is genuinely adequate and anybody insisting otherwise is selling something.

What it means for forms

The practical consequence most relevant to a small business site.

Anything a visitor types into a form travels to your server, and without a certificate it travels readable by anybody on the network between them.

For a contact form containing a name and a phone number that is a modest risk, and browsers now warn about it regardless of how modest.

Which means the warning appears at the precise moment somebody was about to make contact, which is the worst possible place on the site to alarm anybody.

That alone justifies the twenty minutes, whatever your assessment of the underlying risk.

Getting one

Easier than it used to be, and free in most cases.

Most hosts now offer automatic certificates as a setting, issued and renewed without anybody doing anything.

If yours does, turn it on and the whole subject disappears.

If yours charges for something a competitor gives away, that is worth noting when the hosting renewal comes round.

The one thing to get right is renewal. A certificate that expires produces a full-page browser warning that stops visitors entering at all, and it is an entirely self-inflicted outage.

Mixed content

The problem that appears after adding a certificate and confuses people.

If the page is served securely but loads an image or a script over an insecure connection, the browser reports the page as only partly secure, and the padlock does not appear.

Which means a site can hold a perfectly valid certificate and still show a warning, because one old image is being loaded the wrong way.

The fix is finding and updating those references, which most platforms have a tool or a plugin for.

It is worth checking after installing a certificate rather than assuming the job is done, because this is the most common reason it appears not to have worked.

The counter-case

Where a paid certificate is worth considering.

Anywhere a client or a tender explicitly requires a particular type, which happens in public sector and enterprise work.

Businesses handling genuinely sensitive information where the additional verification forms part of a wider compliance position.

And where a warranty attached to the certificate has some value in your specific arrangements.

For everybody else, the free automatic option provides identical encryption and identical treatment by every browser.

What visitors actually think it means

Worth knowing if you are relying on it as a trust signal, because there is a gap between the technical meaning and the public one.

Many people read the padlock as an endorsement: that somebody checked the business and found it legitimate.

That belief is what makes it useful to fraudulent sites, and it is not something you can correct on your own contact page.

What it means practically is that having one gains you nothing in trust, because it is expected, while lacking one costs you a great deal.

Which is why the effort belongs in the other trust signals: a real address, a named person, licence numbers and genuine reviews, none of which anybody can obtain in twenty minutes.

What to check on your own site

  1. Does every page load securely, not just the homepage.
  2. Does the insecure version redirect to the secure one.
  3. Is there a mixed content warning anywhere.
  4. When does the certificate expire, and does it renew automatically.
  5. Do internal links point at the secure version?

The second is frequently missed. A site available at both addresses without a redirect has two versions of every page, which is a duplication problem as well as a security one.

The fifth catches a common leftover from before a certificate was added, where internal links still point at the insecure address and cause an unnecessary redirect on every click.

The expiry question is covered by the same renewal discipline as in when the renewal notice goes to a dead address.


Frequently asked questions

What does the padlock prove?

That traffic is encrypted between browser and server, and that the certificate was issued for that domain. That is the whole guarantee.

What does it not prove?

That the business is real, that the site is safe, that anybody verified who runs it, or that your data is handled properly once it arrives.

Can a fraudulent site have one?

Yes, and most do. Basic certificates are issued automatically to anybody who controls a domain, in minutes, at no cost.

Why do I need one then?

Because the absence is now the signal. Browsers mark sites without one as not secure and warn before form submission, which drives visitors away.

Which type should I buy?

For almost every small business, the free automatic option. Organisation and extended validation cost money and produce no visible difference to visitors.

What is mixed content?

A secure page loading an image or script insecurely, which removes the padlock. It is the most common reason a new certificate appears not to have worked.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Browser marking your site as not secure?

Most hosts now issue certificates free and automatically, and turning it on takes twenty minutes.

Start a Conversation