website-safety

The Padlock Myth: Why HTTPS Doesn't Mean a Website Is Safe

A well-meaning piece of advice that aged badly

For years, the standard safety tip was simple: "look for the padlock". If a website showed the little closed padlock in the address bar and its address began with https://, you were told, it was safe to enter your details. Millions of people learned that rule, and it stuck.

It was reasonable advice a decade ago, when encryption certificates cost money and took effort to obtain, so most casual scammers did not bother. It is dangerously outdated now. Today the padlock is on almost every website — including a large majority of phishing and scam pages. Criminals learned the rule too, and they use it against you: the padlock you were taught to trust is now part of the disguise.

This article explains what the padlock and HTTPS actually prove, what they cannot prove, and what to check instead. If you take one thing away, make it this: the padlock tells you your connection is private, not that the people on the other end are honest.

What HTTPS actually does

When you load a page over https://, your browser and the web server set up an encrypted connection using an SSL certificate (technically its modern successor, TLS). That encryption does two genuinely useful things.

First, it scrambles the data travelling between your device and the site, so that someone snooping on the same public Wi-Fi — in a café, an airport, a hotel — cannot read your password or card number as it goes past. Second, it confirms that you are really connected to the server that holds the certificate for that domain, rather than an imposter machine sitting in the middle.

Those are worth having. You should absolutely avoid entering sensitive information on a plain http:// page with no encryption at all. The problem is not that HTTPS is useless — it is that people were sold it as proof of trustworthiness, which it was never designed to be.

The gap between "encrypted" and "honest"

Here is the crucial distinction. HTTPS secures the pipe between you and the website. It says nothing about who owns the website or what they intend to do with what you send them.

Think of it like posting a letter in a tamper-proof, sealed envelope. The seal guarantees nobody reads your letter on the way. It guarantees nothing about whether the person you are writing to is a fraudster. A scammer with a perfectly valid certificate receives your card details through a beautifully encrypted connection — and then empties your account exactly as they planned. The encryption protected the delivery, not you.

Why almost every scam site now has a padlock

The economics changed. Certificates used to cost money; now they are free and automatic. Services set up to make the web more secure for everyone hand out basic certificates at no charge, in seconds, to anyone who controls a domain — no questions asked about who they are or what they sell. That is genuinely good for the open web. It also means a criminal registering secure-bank-login.com on a Monday morning can have a valid padlock on it by lunchtime.

The result is stark: the padlock has become so common that its presence carries almost no signal, while its absence is now unusual enough to be a mild warning in itself. Security researchers consistently find that the clear majority of phishing sites use HTTPS. Scammers adopted it eagerly, precisely because a generation of shoppers was trained to relax the moment they saw it.

The certificate detail that once mattered — and its catch

Not all certificates are equal. There used to be a meaningful hierarchy:

| Certificate type | What it verifies | Effort to obtain | | --- | --- | --- | | Domain Validation (DV) | Only that the applicant controls the domain | Minutes, free, automated | | Organisation Validation (OV) | The domain plus some business details | Days, some vetting | | Extended Validation (EV) | Rigorous checks on the legal entity | Weeks, real scrutiny |

The overwhelming majority of certificates issued today, including on scam sites, are the cheapest Domain Validation kind — which only ever proved that the applicant controlled the domain, never that they were a legitimate business. Extended Validation once put a company's verified name in the address bar as a stronger signal, but modern browsers stopped displaying that name prominently, so even shoppers who know to look for it usually cannot see it any more. The upshot: you can occasionally inspect a certificate to see who it was issued to, but for everyday purposes the type of certificate is no longer a reliable trust test.

How to actually inspect a certificate

If you are curious, you can still look under the bonnet. On a desktop browser, click the padlock (or the tune/site-information icon beside the address) and choose the option to view the connection or certificate details. You will see who the certificate was issued to and who issued it, along with its valid-from and valid-to dates. On a genuine bank or large retailer, the "issued to" field usually names a recognisable organisation. On a scam site, it will typically show only the domain name and a free issuing authority — technically valid, but revealing nothing about a real business.

The honest conclusion is that this inspection is worth doing occasionally to satisfy your curiosity, but it is no substitute for the checks below. A criminal's Domain Validation certificate is issued to their fraudulent domain and is entirely "valid". Validity is not honesty.

What to check instead

If the padlock is not the answer, what is? The same fundamentals that reveal any scam. The padlock is one small tick on a much longer checklist — never the whole test.

  • Read the domain name. Encryption cannot fix a fake address. https://paypa1-secure.com is still a fraud, padlock and all. Check the exact spelling for lookalike tricks.
  • Check the domain's age and ownership. A recently registered site asking for money is a warning no certificate can offset. See our piece on why a website's age matters.
  • Look at how you are asked to pay. Bank transfer or gift cards only? That is a red flag regardless of HTTPS.
  • Search the brand independently. Reviews and scam reports off-site tell you far more than the padlock ever will.
  • Run the full check. Our guide to recognising a scam website and our article on the red flags of a scam website walk through the signals that actually correlate with fraud.

In short, do everything you would do on the checklist in how to check if a website is legit, and treat the padlock as the bare minimum a site should have, not as a badge of honour.

The phishing angle

The padlock myth is especially dangerous with phishing. A phishing page's whole job is to impersonate a site you trust — your bank, a delivery company, a tax authority — and harvest what you type in. Because these pages are copies of real login screens, they look identical to the genuine article. And because their operators can get a free certificate in minutes, they show the same padlock.

So a customer who was taught "if it has the padlock, it is safe" does the worst possible thing: they see the padlock on the fake bank page, feel reassured, and enter their credentials with confidence. The single tip meant to protect them is the reason they let their guard down. This is why we stress checking the domain name above everything else — on a phishing page, the encryption is real, but the address never quite is.

Before you go

The padlock rule spread because it was simple, memorable and — once — true, which is exactly how it will keep spreading long after it stopped helping. You will hear it from well-meaning relatives, in dated advice columns, even in the odd bank leaflet. Now that you know better, pass the correction on: the padlock means private, not honest, and the address bar deserves the attention the padlock used to get.

For what it is worth, that ordering is baked into the checker being built here at CheckAScam. Encryption on its own counts for little among the signals we weigh, because it no longer separates real sites from fakes; a domain's age, its ownership and its track record do. A tool can gather those facts faster than any of us — but reading the address, character by character, will always be yours to do.

Frequently Asked Questions

Does the padlock icon mean a website is safe?

No. The padlock only means the connection between your browser and the site is encrypted, so data cannot be intercepted and read in transit. It says nothing about who runs the site or whether they are trustworthy. Because encryption certificates are now free and instant, the majority of scam and phishing sites display a padlock too. Treat it as the minimum a site should offer, not as evidence that it deserves your card details.

Should I still avoid websites without HTTPS?

Yes. If a site is on plain `http://` with no padlock at all, do not enter passwords, card numbers or personal details there, because that information could be read by anyone monitoring the network. HTTPS being absent is a genuine warning in 2026, since it has become so standard. Just remember that its presence is not the reassurance it was once sold as — a padlock is necessary but nowhere near sufficient.

How do scam sites get a padlock so easily?

Basic encryption certificates are issued free of charge and automatically to anyone who can prove they control a domain, with no checks on who they are or what business they run. That openness was created to make the whole web more secure, which is a good thing. The side effect is that a criminal can register a fraudulent domain and have a valid padlock on it within minutes, which is why the padlock alone can never confirm a site is honest.

More From CheckAScam

Want more ways to stay safe?

Browse our full library of plain-English guides — how to spot fake shops, safe ways to pay, and how to get your money back if something goes wrong.

Browse the Guides