Is your website secure? What the padlock actually means

Updated August 22, 2026

The short answer: the padlock means the connection between a visitor's browser and your website is scrambled, so nobody sitting between them can read what gets sent. That is all it means. It does not say the website is honest, and it does not say the website is safe. The good news for a first-timer is that this protection comes from something called an SSL certificate, and most website builders and hosting plans set one up for you automatically. Your job is just to check it is working, and to know what the browser warnings mean when it is not.

Quick answer

  • The padlock means information traveling between a visitor and your website is encrypted. Nobody in between, like someone on the same public wifi, can read it.
  • It does not mean the website is trustworthy. Scam websites can show a padlock too.
  • The encryption comes from an SSL certificate. Most website builders and hosting plans include one and turn it on for you.
  • To check your own website, open it and look at the address bar. The address should start with https, and no warning should say "Not secure".
  • Chrome retired the padlock icon in 2023 and shows a small settings icon instead, so a missing padlock in Chrome is normal. The warning that matters is "Not secure".
  • What actually protects a new website is less about the padlock and more about you: a strong password on your builder and domain accounts, and a domain that does not quietly expire.

Here is what the padlock does and does not tell you, how to check your own website in under a minute, and where the real security work actually lives.

What does the padlock actually mean?

Think about sending a letter two ways. A postcard can be read by everyone who handles it along the way. A sealed envelope cannot. The padlock says your website talks to visitors in sealed envelopes.

Without that seal, information moves as the postcard. Someone on the same coffee shop wifi as your visitor could see what they type into your contact form. With the seal, what travels between the visitor and your website is scrambled into nonsense that only the two ends can unscramble.

The seal comes from an SSL certificate. That is a small file that proves your website address really answers for your website, and it switches on the scrambling. You can spot it working in the address bar: the address starts with https instead of http. The extra s is the seal.

Here is the part first-timers are never told: you almost never have to set this up yourself anymore. Website builders and hosting plans include the certificate, install it, and renew it quietly in the background. If you got online with a builder, there is a good chance your padlock has been there since day one without you doing anything.

Why did the padlock disappear in Chrome?

If you open your website in Chrome and see no padlock at all, do not panic. Chrome retired the icon on purpose.

Google explained why when it made the change. The padlock made sense when secure websites were rare, but by 2023 Google reported that 95% of page loads in Chrome on Windows used a secure connection (Google, 2023). When nearly everything is sealed, a seal icon on every page stops meaning much.

The icon was also being misread in a dangerous way. In Google's own research, only 11% of people studied correctly understood what the padlock actually meant (Google, 2021). Many assumed it meant the website itself was trustworthy, which it never did. So in September 2023, Chrome replaced the padlock with a small settings icon (Google, 2023).

What Chrome kept is the warning in the other direction. A website without encryption gets marked "Not secure" right in the address bar, and Safari shows a similar warning. That is the signal worth watching, in both directions: on your own website it is a problem to fix, and on other websites it is a reason to type nothing personal.

How do you check if your own website is secure?

This takes under a minute, and it is worth doing in the first week your website is online:

  1. Open your website in a browser, on your phone or computer.
  2. Look at the address bar. The full address should start with https://. Some browsers hide that part, so tap or click the address bar to see the whole thing.
  3. Make sure there is no "Not secure" warning next to your address.
  4. Now type your address with http:// at the front, without the s, and press enter. A properly set up website will bounce you to the https version automatically.
  5. Click through a few pages, including any page with a form. The warning should not appear anywhere.

If all of that checks out, your website is sealed and you can stop thinking about certificates. This check fits naturally into the same once-over as the rest of our list of what to do the week after your website goes online.

What if your website says Not secure?

It almost always means the certificate is missing, expired, or not switched on yet. With a builder, this is a settings problem, not a technical rescue mission:

  • You just connected your own domain. Certificates are issued per address, so a freshly connected domain can take a few hours to get its own. If your website got online today, wait a few hours and check again before touching anything.
  • The certificate option is off. Look in your builder or hosting settings for words like SSL, https, or secure, and make sure the option is turned on, including any setting that redirects http to https. Our plain guide to what web hosting actually is explains where these pieces live.
  • One page pulls in something old. If only one page warns, it is usually an image or video embedded from an old http address. Remove that item and add it back fresh.
  • None of that fixes it. Send your builder or host a message saying your website shows "Not secure" and ask them to check the SSL certificate. This is a routine request they handle every day. You should not need to buy anything.

Not online yet, and this is the stuff you were dreading?

The technical layer mostly handles itself. The part that decides how your website turns out is the description you feed the AI builder. Describe what you are starting in one plain box, and Expert Built turns it into the detailed prompt the builder needs, so your website comes out built around you instead of generic, with the sealed connection included from day one.

Get started

Can a scam website have a padlock?

Yes, easily. Certificates prove a website address answers for itself and that the connection is sealed. They do not check whether the people behind the address are honest. A fake shop can get a certificate the same way you did, so a padlock on someone else's website is not a reason to trust it. Google's own advice is to check the name in the address bar, not just the security icon, and to stay careful with personal information either way.

Flip that around and it tells you something about your own website: the seal is expected, not impressive. Visitors will not trust you because of a padlock. They trust real details, clear photos of your work, a way to reach a real person, and words from past customers. If that trust layer is your next job, start with our guide on asking customers for reviews.

What actually keeps your first website secure?

Once the connection is sealed, the realistic risks to a small website are not movie-style hacking. They are these, and they are all boring and manageable:

  • Your accounts are the real front door. Anyone who gets into your builder account or your domain account controls your website, no hacking skills required. Use a strong password you use nowhere else, and turn on two-step login if it is offered. This one habit outweighs everything else on this list.
  • Your domain has to stay yours. An expired domain takes your website and email down and can even be bought by someone else. Keep auto-renew on and your payment card current. Here is what happens when a domain or hosting plan expires if you want the full picture.
  • The software updates are not your job. With a builder, the company patches the machines your website runs on. That is a real advantage over running your own server, and it means there is no update chore for you to fall behind on.
  • Card numbers should never touch your website. If you sell things, let a payment company handle the card step, which is how builder checkouts work anyway. Our guide on taking payments on your website walks through it.
  • Collect less, worry less. Every piece of visitor information you store is something you have to protect. A contact form that asks for a name, an email address, and a message is plenty for most first websites.

The padlock question that brought you here turns out to be the easy part. Check the address bar once, fix the warning if you ever see one, and spend your care on the password and the domain. That is what secure looks like for a first website.

Frequently asked questions

Do you have to pay for an SSL certificate?
Usually not. Most website builders and hosting plans include the certificate and renew it for you, at no extra charge, because nonprofit organizations now issue these certificates to anyone who asks. Paid certificates still exist, and big companies buy them for extra vetting, but a first website does not need one. If a company tries to sell you a certificate as a required add-on, check your builder's settings first, because there is a good chance you already have one.
Does a secure website help you show up on Google?
A little, and Google has said so itself. Back in 2014 Google announced it uses a secure connection as a ranking signal, but called it a very lightweight one that affected fewer than 1% of searches at the time. The bigger effect is on people, not rankings. If a browser warns visitors that your website is not secure, many of them leave before reading a word, and a website nobody stays on will not do well anywhere.
What is the difference between SSL, TLS, and HTTPS?
They are three names for the same idea, which is why the jargon feels confusing. SSL is the old name for the technology that encrypts the connection, TLS is the newer version that replaced it, and HTTPS is what the website address is called when that encryption is switched on. People still say SSL certificate out of habit, even though the technology behind it is TLS. You do not need to remember any of this. If your address starts with https and no browser warns about it, the whole stack is doing its job.
Do you need extra security software for your website?
If you built it with a website builder, no. There is no antivirus to install on a website like this, because the builder company runs the computers your website lives on and keeps that software patched. Security plugins are a thing from the WordPress world, where you rent a server and maintain the software yourself. Your effort is better spent on the things only you control: a strong password on your builder and domain accounts, two-step login where offered, and keeping your own computer clean.

Get an expert built website in minutes

Describe your business and we'll do the rest.

Get started

← All guides