You are about to enter your card number on a checkout page. Something about the site feels slightly off, though you cannot say exactly what.
Before you type anything, you want one quick way to confirm this. Is the connection actually safe?
That confirmation takes less than ten seconds in most browsers. This guide shows you exactly where to look. It also covers deeper tools for when you manage the site yourself.
The 10-second check
- Look at the address bar for https:// and a closed padlock icon.
- Click the padlock, then “Connection is secure,” to see who issued the certificate.
- An open padlock or a “Not Secure” label means the certificate is missing or broken.
- Managing the site yourself? Run it through SSL Labs for a full technical grade.
The Fast Way: Check the Address Bar
Almost every visitor only needs this one glance. Look at the very start of the URL, right before the website address.
- A closed padlock and https:// mean the connection is encrypted right now.
- An open padlock, an info icon, or “Not Secure” means the certificate is missing or misconfigured.
- A red warning page, rather than the site itself, means the certificate has expired or is broken.
That single glance answers the question for casual browsing. Entering a password or a card number deserves one extra step, covered next.
The Careful Way: View the Certificate Details
Clicking the padlock tells you far more than the icon alone. Here is what that click reveals, on any major browser.
On desktop, in Chrome, Edge, or Firefox
- Click the padlock or tune icon, just left of the web address.
- Select “Connection is secure” from the menu that appears.
- Click the certificate icon, or “Certificate is valid,” to open full details.
- Check the issuer, the domain it covers, and the expiration date shown there.
If the direct certificate button seems missing, developer tools always work instead. Press F12, or Ctrl+Shift+I on Windows, then open the Security tab.
Click “View certificate” there to see the same details.
On Android and iPhone
- Android: tap the padlock next to the address, then tap “Certificate.”
- iPhone or iPad: tap the three dots in the top corner, then “Site Information.”
Mobile screens show slightly less detail than desktop browsers do. For a full technical report on the go, an online checker tool works too. Any phone browser can load one.
What the Certificate Details Actually Tell You
Once the certificate window opens, three fields matter most. Everything else on that screen is secondary detail.
| Field | What it shows | What to check |
| Issued to | The domain name the certificate covers | It should match the site you are actually visiting |
| Issued by | The Certificate Authority that verified the site | Trusted names include Let’s Encrypt, DigiCert, and Sectigo |
| Valid until | The certificate’s expiration date | A date in the past means the certificate has lapsed |
A domain mismatch or an expired date is exactly what triggers a browser warning page.
A mismatch between the domain shown and the domain you typed is a real warning sign. That pattern shows up on phishing pages that copy a certificate from elsewhere.
The Thorough Way: Online SSL Checker Tools
Browser checks confirm that a certificate exists and looks valid today. They do not check the server’s full configuration behind that certificate.
If you manage the website, that configuration matters. A free online checker scans far deeper than any browser padlock does.
- Qualys SSL Labs gives a full letter grade, from A+ down to F, for the setup.
- SSL Shopper’s checker confirms installation and lists the exact expiration date.
- DigiCert’s diagnostic tool inspects the issuer and serial number in detail.
Enter the domain name, click check, and wait about a minute. The report flags weak protocols, missing intermediate certificates, and looming expiry dates.
Site owners should run this scan every few months. Do not wait until something breaks.
Reading Page Source for a Specific Problem
One narrow issue needs a slightly different check: mixed content. This happens when a secure page still loads some resources over plain HTTP.
Right-click the page and choose “View Page Source,” or press Ctrl+U. Search that source for http:// using Ctrl+F.
Any image, script, or stylesheet still loading that way weakens the page’s security. That is true even when the page itself shows HTTPS.
How to Spot a Look-Alike Checkout Page
For example, if someone is shopping for shoes and clicking an ad link. The page looks identical to the real store, down to the logo and layout.
She glances at the address bar out of habit. The URL shows shoestore-secure-payments.net, not the store’s real domain.
A padlock and https:// are both present, since scam sites can hold valid certificates too.
She clicks the padlock anyway, to check the issued-to field. It confirms the certificate covers shoestore-secure-payments.net, the wrong domain entirely.
A valid certificate on the wrong domain is still a red flag, not proof of safety.
This is exactly why the padlock alone is not enough.
A certificate proves encryption, not honesty about who owns the site.
SSL vs TLS: Does the Difference Matter to You?
You will see both terms used, often on the very same page. Here is the short version of why.
SSL was the original protocol, and it has been retired for years now.
TLS, its modern successor, is what every current browser and server actually uses. The industry kept saying SSL out of habit, and the name stuck.
For a visitor checking a padlock, this distinction changes nothing practical. A valid certificate today is a TLS certificate, whatever name the page uses for it.
Why an Expired or Missing Certificate Costs You Visitors
A browser warning does not just look bad; it actively drives people away. Surveys on shopper behavior say the same thing consistently.
Most people avoid an unsecured checkout page entirely.
Google also treats HTTPS as a ranking signal, however small on its own. The higher cost arrives indirectly.
It comes through the bounce rate that a warning page creates. Visitors who see “Not Secure” rarely stay to find out why.
Why Some Certificates Show More Than Just a Padlock
Not every certificate does the same depth of checking. A Domain Validated certificate only confirms that someone controls the domain, nothing more.
An Organization Validated certificate goes further, checking that a real registered business sits behind the site.
Extended Validation goes the furthest of all, with a rigorous background check on the company itself.
Browsers no longer show a green address bar for EV certificates, the way older versions once did.
The underlying trust difference still exists, though, and shows up in the certificate details. For a blog, DV is plenty. For a bank or a large store, OV or EV signals more.
If You Manage the Site: Fixing a Missing or Broken Certificate
Most hosting providers now include a free SSL certificate with every plan. Truehost, for example, bundles Let’s Encrypt SSL automatically across all its hosting plans.
Renewal happens for you every 90 days.
If your site still shows no padlock, do not worry. The fix is usually a short one. Log in to your hosting control panel first. Then look for an SSL or security section.
- Confirm a free Let’s Encrypt certificate is active for your domain.
- If not, issue one from your control panel, which usually takes minutes.
- For an eCommerce or finance site, consider an Organization or Extended Validation certificate instead.
- Set a calendar reminder to recheck the expiry date every few months, as a backup to auto-renewal.
Truehost’s paid SSL certificates start from about $5.50 a year. That covers a single domain. Domain-validated certificates are issued within minutes.
Organization or Extended Validation types take a few days instead, since they verify your actual business.
How Often Do Certificates Actually Expire?
Free Let’s Encrypt certificates run on a 90-day cycle, renewing automatically in the background. Paid certificates from other authorities often run for one full year instead.
Automatic renewal fails more often than people expect, usually from an expired payment card or a misconfigured server.
That single failure is exactly what an occasional manual check catches early.
The Bottom Line
So the next time a checkout page feels slightly off, trust that instinct. Glance at the address bar for https:// and a closed padlock first.
Click through to the certificate details if anything still feels uncertain.
If you manage the website in question, build a small habit around it. Run it through an online checker every few months.
That single habit catches an expiring certificate early. A visitor never has to see the warning at all.
Need to secure a site of your own? See Truehost’s SSL certificates. Or check that your hosting plan already includes one for free.
Domain RegistrationFind and register the perfect domain for your website.
.COM DomainChoose a widely recognized domain to build global credibility.
Domain TransferSeamless domain transfers with zero downtime and complete control.
All TLDsFind and register your perfect domain. Choose from local and global extensions.
whoisCheck domain ownership details, expiration dates, and registrar information.
US DomainRegister a .US domain and build trust in the USA.
Web HostingEverything your website needs to run smoothly
WordPress HostingWordPress hosting that just works
Windows HostingReliable hosting for Windows environments
Reseller HostingTurn hosting into your business
Email HostingEmail that looks professional and works anywhere
cPanel HostingFull control of your hosting with cPanel
Affiliate ProgramJoin as a partner and earn commissions on every referral you send our way.
Vps HostingScalable virtual servers that expand as you need.
Dedicated ServersGet complete access and full control over your dedicated physical server.
Managed vpsNot tech-savvy? We will take care of everything with our fully managed VPS hosting for you.





