SECURITYJune 6, 2026 · 8 min read·0

The HTTPS Padlock Lie: Why SSL Doesn’t Mean a Website Is Safe to Pay On

The padlock icon only proves the connection is encrypted. It doesn’t verify who runs the site. Most phishing pages in 2026 have valid SSL — here’s what to actually check.

S
DomainScan
𝕏 Share
Security

Somewhere between 2014 and 2020, the internet collectively agreed on a piece of folk wisdom: look for the padlock. If the little lock icon is in the address bar, the site is safe. If it’s not, run.

That advice was true enough in 2014 to be useful. In 2026 it’s actively misleading. Studies from the Anti-Phishing Working Group have shown that the majority of phishing sites for several years running now carry valid SSL certificates. The padlock has become the scammer’s favorite trust signal — because they get it for free and the user trusts it for free.

This piece explains what the padlock actually proves, what it doesn’t, and what to check instead before you enter a card number.

What the padlock actually means

The padlock proves exactly three things:

  1. The connection is encrypted. Nobody between you and the server can read what you’re sending. Your card number won’t be intercepted on the network.
  2. The server’s identity hasn’t been hijacked. The site you’re connected to actually controls the domain in the URL. A man-in-the-middle attack can’t silently swap pages on you.
  3. The certificate was issued by a trusted authority. Some entity — your browser’s trust store agrees with this — vouched that whoever owns the domain proved they owned it.

That’s the whole list. Notice what’s missing:

  • The padlock does not say the site is honest.
  • The padlock does not say the operator is a real business.
  • The padlock does not say the page won’t steal your money.
  • The padlock does not even say the site isn’t actively phishing right now.
Mental model
The padlock is like a sealed envelope. It guarantees no one tampered with the letter on the way to you. It says nothing about whether the person who wrote the letter is honest.

How free SSL changed the game

Until 2015, SSL certificates cost money. The barrier was small — usually $10–50 a year — but small enough that the average phishing operator running 20 domains decided it wasn’t worth it. Phishing sites were predominantly HTTP. The padlock heuristic worked because it correlated with operators who’d at least bothered to spend money on infrastructure.

Let’s Encrypt launched in late 2015 and changed this overnight. Free, automated, valid for 90 days, renewable forever. Wonderful for the open web. Also wonderful for phishing. By 2018, the majority of phishing domains had Let’s Encrypt certificates. The padlock heuristic stopped being a useful signal — and yet most internet safety advice never updated.

Today every meaningful certificate authority offers free or near-free DV (domain-validated) certificates. A scammer can spin up a fully HTTPS phishing site, including the padlock, in under fifteen minutes. The bar is gone.

DV vs OV vs EV certificates

Not all certificates require the same level of proof. There are three tiers, and the difference matters.

  • DV (Domain Validation). The CA verifies one thing: you control the domain. A scammer who bought flipkart-deals.shop can get a DV cert for it in minutes. Let’s Encrypt, ZeroSSL, and most free CAs only issue DV.
  • OV (Organization Validation). The CA verifies that a real registered business owns the domain. Requires paperwork — business registration, phone verification, sometimes a physical address check. Takes days, costs ~$50–150/year. Real e-commerce often uses OV.
  • EV (Extended Validation). The strictest tier. CA performs detailed background checks on the business — legal existence, operational presence, identity of the requester. Costs $200+/year and takes a week or more. Banks and large financial institutions still use EV.

The catch: browsers no longer visually distinguish between these three tiers. Chrome stopped showing the green “Trusted” bar for EV certs in 2019. Firefox followed. Today, a $0 Let’s Encrypt cert and a $300 EV cert from DigiCert show the exact same padlock icon.

You have to click into the certificate details to see which kind it is — and almost no user ever does.

What to check beyond the padlock

If the padlock no longer works as a single-bit safety check, what should you actually look at? Three things, fast:

  1. The certificate issuer. A Let’s Encrypt or ZeroSSL cert on a site claiming to be a major retailer is a red flag. Real retailers usually pay for OV/EV from a paid CA — Sectigo, DigiCert, GlobalSign, Entrust.
  2. The certificate’s issue date vs the domain’s age. A certificate issued three days ago, on a domain registered last week, on a site asking for card details, is a scam pattern on autopilot. Match the timeline against the brand it claims to be.
  3. The certificate’s Subject Alternative Names (SANs). A real company’s cert usually covers a sensible list of related subdomains. A scam cert often covers wildly unrelated domains because the same CA bundle was reused across many fake sites.
Inspect any SSL certificate
Issuer, validity dates, SANs, full chain — without opening the browser dev tools.
Try it

Why browsers stopped showing the green bar

A small history lesson, because it explains the current state of things. Until about 2019, EV certificates triggered a green address bar with the company’s name displayed prominently — PayPal, Inc. (US) right next to the URL. The visual was supposed to say, this is the real PayPal.

Research over several years showed the same uncomfortable thing again and again: users didn’t notice the green bar. They didn’t notice when it was missing. Scammers worked around it with shell companies and similar-sounding names. The signal was strong in theory and almost useless in practice.

Chrome and Firefox both decided the green bar was creating false confidence without measurable improvement in safety. They removed it. The downside is that EV certificates now have almost no visible signal — but the upside is that the padlock, finally, doesn’t pretend to mean more than it does.

The new rule
Treat the padlock as table stakes. Its absence is a hard no. Its presence is no signal at all. The real safety check is everything else — domain age, WHOIS, reverse IP, blacklist, certificate issuer.

FAQ

If I see HTTPS, is the website safe?

No. HTTPS only means the connection is encrypted and the certificate is valid. It says nothing about whether the operator is trustworthy. The majority of phishing sites in 2026 use HTTPS.

Should I worry about a site without HTTPS?

Yes — but for a different reason than people think. HTTP-only sites in 2026 are rare and usually indicate either neglect (the operator hasn’t kept up with basic web hygiene) or an old, abandoned page. Don’t enter sensitive data on HTTP, but don’t treat HTTPS as the opposite.

How can I tell what kind of SSL certificate a site has?

Click the padlock in your browser and view the certificate details. Look for “Organization” in the subject — if it’s populated, you’re looking at OV or EV. If only the domain is listed, it’s a DV certificate, which means the CA didn’t verify the business behind it.

Is Let’s Encrypt bad?

Not at all. Let’s Encrypt is a public good that secured millions of websites that would otherwise still be on HTTP. The problem is using presence of Let’s Encrypt as a trust signal. It proves the operator could pass a domain-control check and run a renewal script. Nothing more.

#https#ssl certificate#padlock icon#website safety#phishing#lets encrypt#certificate authority
S
Writes about web security, certificate authorities and the gap between what users think padlocks mean and what they actually mean.
RELATED POSTS
Security
SECURITYSeptember 21, 2026 · 10 min·0

47-Day SSL Countdown: Live Timer + What Changes in Every SC-081v3 Phase

A live countdown to 2029-03-15, the day publicly-trusted TLS certificates cap at 47 days. Read what SC-081v3 actually voted, the four phase dates (200 → 100 → 47), the 10-day DCV reuse rule, the 8× renewal math against a 32% CLM adoption rate, and a phase-by-phase playbook you can start this quarter.

RRahul
Security
SECURITYSeptember 10, 2026 · 10 min·0

BigBear 2.0 (Sept 2026): 3,331 Microsoft 365 Victims and the End of MFA-Only Defense

CloudSEK exposed the BigBear 2.0 phishing-as-a-service network — 5,137 stolen credential records, 461 organizations across 40+ countries, and 474 fully MFA-authenticated Microsoft 365 sessions hijacked from a fleet of 42 Vultr proxies. Here is why passwords plus MFA no longer stop credential theft, and how infrastructure-level scanning catches the pattern.

SSindhu
Security
SECURITYSeptember 10, 2026 · 9 min·0

Diwali 2026 Phishing Playbook: 828 Fake Ad Domains, 1-in-3 Indians Duped, and the UPI + Deepfake Trap

McAfee's 2025 Global Holiday Shopping Scams Study — the last full-year India benchmark before Diwali 2026 — found one in three Indians duped by festive-season scams, 37 percent suffering financial loss, average loss over ₹41,500. Quick Heal's Seqrite Labs identified 828 distinct phishing domains running Facebook Ads campaigns in one festive window. Here is the 2026 playbook — the brands attackers impersonate, the domain patterns Domainscan catches, and the 30-second check to run before every festive payment.

AAvinash
NEW POSTS, NO SPAM

One short email when we publish.

~2 posts a month, no marketing, unsubscribe in one click.