India English
Kenya English
United Kingdom English
South Africa English
Nigeria English
United States English
United States Español
Indonesia English
Bangladesh English
Egypt العربية
Tanzania English
Ethiopia English
Uganda English
Congo - Kinshasa English
Ghana English
Côte d’Ivoire English
Zambia English
Cameroon English
Rwanda English
Germany Deutsch
France Français
Spain Català
Spain Español
Italy Italiano
Russia Русский
Japan English
Brazil Português
Brazil Português
Mexico Español
Philippines English
Pakistan English
Türkiye Türkçe
Vietnam English
Thailand English
South Korea English
Australia English
China 中文
Canada English
Canada Français
Somalia English
Netherlands Nederlands

How to Check If a Website Has a Valid SSL Certificate

Buy domains, business emails, hosting, VPS and more: Get Started

You are about to enter your card number on a checkout page. Something about the site feels slightly off, though you cannot say exactly what.

Before you type anything, you want one quick way to confirm this. Is the connection actually safe?

That confirmation takes less than ten seconds in most browsers. This guide shows you exactly where to look. It also covers deeper tools for when you manage the site yourself.

The 10-second check

  • Look at the address bar for https:// and a closed padlock icon.
  • Click the padlock, then “Connection is secure,” to see who issued the certificate.
  • An open padlock or a “Not Secure” label means the certificate is missing or broken.
  • Managing the site yourself? Run it through SSL Labs for a full technical grade.

The Fast Way: Check the Address Bar

Almost every visitor only needs this one glance. Look at the very start of the URL, right before the website address.

  • A closed padlock and https:// mean the connection is encrypted right now.
  • An open padlock, an info icon, or “Not Secure” means the certificate is missing or misconfigured.
  • A red warning page, rather than the site itself, means the certificate has expired or is broken.

That single glance answers the question for casual browsing. Entering a password or a card number deserves one extra step, covered next.

The Careful Way: View the Certificate Details

Clicking the padlock tells you far more than the icon alone. Here is what that click reveals, on any major browser.

On desktop, in Chrome, Edge, or Firefox

  • Click the padlock or tune icon, just left of the web address.
  • Select “Connection is secure” from the menu that appears.
  • Click the certificate icon, or “Certificate is valid,” to open full details.
  • Check the issuer, the domain it covers, and the expiration date shown there.

If the direct certificate button seems missing, developer tools always work instead. Press F12, or Ctrl+Shift+I on Windows, then open the Security tab. 

Click “View certificate” there to see the same details.

On Android and iPhone

  • Android: tap the padlock next to the address, then tap “Certificate.”
  • iPhone or iPad: tap the three dots in the top corner, then “Site Information.”

Mobile screens show slightly less detail than desktop browsers do. For a full technical report on the go, an online checker tool works too. Any phone browser can load one.

What the Certificate Details Actually Tell You

Once the certificate window opens, three fields matter most. Everything else on that screen is secondary detail.

FieldWhat it showsWhat to check
Issued toThe domain name the certificate coversIt should match the site you are actually visiting
Issued byThe Certificate Authority that verified the siteTrusted names include Let’s Encrypt, DigiCert, and Sectigo
Valid untilThe certificate’s expiration dateA date in the past means the certificate has lapsed

A domain mismatch or an expired date is exactly what triggers a browser warning page.

A mismatch between the domain shown and the domain you typed is a real warning sign. That pattern shows up on phishing pages that copy a certificate from elsewhere.

The Thorough Way: Online SSL Checker Tools

Browser checks confirm that a certificate exists and looks valid today. They do not check the server’s full configuration behind that certificate.

If you manage the website, that configuration matters. A free online checker scans far deeper than any browser padlock does.

  • Qualys SSL Labs gives a full letter grade, from A+ down to F, for the setup.
  • SSL Shopper’s checker confirms installation and lists the exact expiration date.
  • DigiCert’s diagnostic tool inspects the issuer and serial number in detail.

Enter the domain name, click check, and wait about a minute. The report flags weak protocols, missing intermediate certificates, and looming expiry dates. 

Site owners should run this scan every few months. Do not wait until something breaks.

Reading Page Source for a Specific Problem

One narrow issue needs a slightly different check: mixed content. This happens when a secure page still loads some resources over plain HTTP.

Right-click the page and choose “View Page Source,” or press Ctrl+U. Search that source for http:// using Ctrl+F.

Any image, script, or stylesheet still loading that way weakens the page’s security. That is true even when the page itself shows HTTPS.

How to Spot a Look-Alike Checkout Page

For example, if someone is shopping for shoes and clicking an ad link. The page looks identical to the real store, down to the logo and layout.

She glances at the address bar out of habit. The URL shows shoestore-secure-payments.net, not the store’s real domain. 

A padlock and https:// are both present, since scam sites can hold valid certificates too.

She clicks the padlock anyway, to check the issued-to field. It confirms the certificate covers shoestore-secure-payments.net, the wrong domain entirely. 

A valid certificate on the wrong domain is still a red flag, not proof of safety.

This is exactly why the padlock alone is not enough. 

A certificate proves encryption, not honesty about who owns the site.

SSL vs TLS: Does the Difference Matter to You?

You will see both terms used, often on the very same page. Here is the short version of why.

SSL was the original protocol, and it has been retired for years now. 

TLS, its modern successor, is what every current browser and server actually uses. The industry kept saying SSL out of habit, and the name stuck.

For a visitor checking a padlock, this distinction changes nothing practical. A valid certificate today is a TLS certificate, whatever name the page uses for it.

Why an Expired or Missing Certificate Costs You Visitors

A browser warning does not just look bad; it actively drives people away. Surveys on shopper behavior say the same thing consistently. 

Most people avoid an unsecured checkout page entirely.

Google also treats HTTPS as a ranking signal, however small on its own. The higher cost arrives indirectly. 

It comes through the bounce rate that a warning page creates. Visitors who see “Not Secure” rarely stay to find out why.

Why Some Certificates Show More Than Just a Padlock

Not every certificate does the same depth of checking. A Domain Validated certificate only confirms that someone controls the domain, nothing more.

An Organization Validated certificate goes further, checking that a real registered business sits behind the site. 

Extended Validation goes the furthest of all, with a rigorous background check on the company itself.

Browsers no longer show a green address bar for EV certificates, the way older versions once did. 

The underlying trust difference still exists, though, and shows up in the certificate details. For a blog, DV is plenty. For a bank or a large store, OV or EV signals more.

If You Manage the Site: Fixing a Missing or Broken Certificate

Most hosting providers now include a free SSL certificate with every plan. Truehost, for example, bundles Let’s Encrypt SSL automatically across all its hosting plans. 

Renewal happens for you every 90 days.

If your site still shows no padlock, do not worry. The fix is usually a short one. Log in to your hosting control panel first. Then look for an SSL or security section.

  • Confirm a free Let’s Encrypt certificate is active for your domain.
  • If not, issue one from your control panel, which usually takes minutes.
  • For an eCommerce or finance site, consider an Organization or Extended Validation certificate instead.
  • Set a calendar reminder to recheck the expiry date every few months, as a backup to auto-renewal.

Truehost’s paid SSL certificates start from about $5.50 a year. That covers a single domain. Domain-validated certificates are issued within minutes. 

Organization or Extended Validation types take a few days instead, since they verify your actual business.

How Often Do Certificates Actually Expire?

Free Let’s Encrypt certificates run on a 90-day cycle, renewing automatically in the background. Paid certificates from other authorities often run for one full year instead.

Automatic renewal fails more often than people expect, usually from an expired payment card or a misconfigured server. 

That single failure is exactly what an occasional manual check catches early.

The Bottom Line

So the next time a checkout page feels slightly off, trust that instinct. Glance at the address bar for https:// and a closed padlock first. 

Click through to the certificate details if anything still feels uncertain.

If you manage the website in question, build a small habit around it. Run it through an online checker every few months. 

That single habit catches an expiring certificate early. A visitor never has to see the warning at all.

Need to secure a site of your own? See Truehost’s SSL certificates. Or check that your hosting plan already includes one for free.

Anne Purity
Author

Anne Purity

Conversion Focused SEO Copywriter Nairobi, Kenya

Anne is a conversion-focused SEO copywriter specializing in the web hosting and domain industry. She creates high-performing content that not only ranks on search engines but also turns visitors into customers. By combining keyword strategy with user intent and persuasive messaging, she helps businesses attract qualified traffic and drive meaningful growth.

View All Posts