All terms
Glossary

SSL/TLS (the padlock symbol)

Encrypts only the connection between browser and server – it is NOT proof of the provider’s legitimacy.

DDennis BöllingFounder · QAD SoftUpdated 2026-07-26
Definition

What does SSL/TLS (the padlock symbol) mean?

SSL (Secure Sockets Layer) and its successor TLS (Transport Layer Security) are encryption protocols that secure data transmission between browser and web server – recognisable by the “https” in the address and the padlock symbol in the browser. They prevent third parties from reading the transmitted data (e.g. entered payment details) while it is in transit.

The crucial thing to understand: SSL/TLS says something only about the encryption of the connection – nothing about the identity, legitimacy or intent of the website operator behind it. Free, automated certificates (e.g. from Let’s Encrypt) are standard today and are used by reputable shops just as much as by fake shops – a padlock symbol has long ceased to be a distinguishing feature of reputable providers.

Technically there are three levels of scrutiny. A domain-validated certificate (DV) only confirms that the applicant controls the domain – that can be done fully automatically in minutes and costs nothing. An organisation-validated certificate (OV) additionally verifies that the company exists; an extended validation certificate (EV) verifies its identity as well. In practice the vast majority of all websites – good and bad alike – use the simplest level.

Earlier “Extended Validation” certificates with a visible company check in the browser now play virtually no role; modern browsers barely highlight them anymore. The browser display therefore no longer reveals how strictly a certificate was vetted – the difference between one issued automatically in 60 seconds and one checked by hand has become invisible to visitors.

A few clicks still yield usable clues. Click the padlock and look at the certificate details: which domain was it issued for, since when is it valid, and who issued it? A certificate that has only existed for a few days sits badly with a shop advertising many years of experience. In addition, all issued certificates are visible in public certificate transparency logs – there you can trace since when certificates have existed for a domain at all.

A typical abuse case shows why the padlock says nothing about trust: a phishing page on a typo domain – for instance with swapped letters or an extra word appended to the domain name – obtains a valid free certificate within minutes. The browser then dutifully shows the padlock, because the connection to precisely that forged domain is correctly encrypted. Encrypted does not mean trustworthy; it only means not readable by others.

In practice, TLS protects above all against eavesdroppers on the transmission path – in an open Wi-Fi network in a café, a hotel or an airport, for example. Without encryption anyone on the same network could capture the address and card details you enter. That is exactly what the technology was built for, and it does that job reliably. It was never meant to say anything about the honesty of the other side.

Browser warnings should therefore be taken seriously even when they look innocuous. An expired certificate, a certificate issued for an entirely different domain, or a page loading part of its content unencrypted (“mixed content”) are substantive faults. With a shop you are about to entrust with your address and payment details, that is a good moment to abandon the process.

A concrete check: click the padlock and compare the domain named in the certificate character by character with what stands in the address bar. On a rebuilt page the two will match – the forgery lies in the domain name itself. That is precisely why this step does not replace reading the address but complements it: only once the domain really is the expected one does the certificate say anything useful.

A second clue is the issue date. A domain whose first certificate is only a few days old was until recently either not in operation at all or reachable without encryption. For a shop advertising many years of experience that is a plain contradiction – and, unlike marketing copy, it cannot be argued away.

In short: the padlock answers the question “can anyone read along?” with no. It does not answer the question “will I get my goods?” at all. Anyone who confuses the two is treating as a quality mark the one property that every operator in the world can obtain for free in a matter of minutes.

An https padlock is thus a technical minimum feature, not proof of trust. If it is missing altogether, however, that is a strong warning sign today: a shop without encryption transmits address and payment data in plain text and is simply not up to date. The padlock must therefore always be assessed together with the legal notice, payment methods, reviews and trust seals – it works as an exclusion criterion, not as a seal of quality.

Unsure about a specific shop?

Our fake-shop check evaluates over 30 trust features – free and in seconds.

Check a shop for free