By Eric L.
09/08/2026 · 6 MIN READ

HTTPS is HTTP over TLS encryption: data between your browser and the site can't be read or altered in transit, and the site proves it controls the domain in the address bar.

The padlock says exactly that and nothing more. It doesn't say the site is honest, safe or who it claims to be: phishing pages almost always have HTTPS, because a certificate takes a minute and costs nothing. Knowing what the padlock guarantees and what it doesn't is more useful than just looking for it. The domain is also exactly what a short link or a QR code hides from you until it's too late; how to see it ahead of time is in how to check a link or QR code before you open it.

THE PADLOCK MEANSFIG. 01
connection encrypted      ✓
site owns the domain      ✓
site is honest            ✗
site is not phishing      ✗
ISP cannot see the domain ✗
    └─ phishing pages have HTTPS too

What happens in an HTTPS connection

  1. Your browser connects to the server and asks to start TLS (the padlock in your address bar).
  2. The server sends a certificate: a document in which a certificate authority vouches that this key belongs to this domain.
  3. Your browser checks the authority's signature, the expiry date, and that the domain actually matches.
  4. The two sides agree on a session key, and everything after that is encrypted.

The current version is TLS 1.3: one fast handshake, and only strong algorithms on the menu.

WHAT HAPPENS ON CONNECTIONFIG. 02
browser asks for the certificate
  ├─ issued by a known authority?
  ├─ issued for this domain?
  └─ still valid?
then both sides agree on keys

What HTTPS protects

  • Content: pages, forms, passwords, card numbers, messages. Your ISP, the coffee shop Wi-Fi and anyone in between see only an encrypted stream.
  • Integrity: nobody along the way can slip an ad, a script or a swapped link into the page you asked for.
  • Domain authenticity: you're talking to whoever controls the domain in the address bar, not to someone who intercepted the connection.
WHAT THE PADLOCK ACTUALLY SEALSFIG. 03
content and passwords      sealed
tampering along the way    detected
site you are visiting      exposed
that you visited at all    exposed
Encryption and privacy are two different promises, and the padlock only makes one of them.

What HTTPS doesn't protect

  • The site's honesty. yourbank-secure-login.com with a padlock isn't your bank. The padlock confirms the domain, not the intent. Read the address, not the icon.
  • The site's name from your ISP. The domain travels in plain text in the DNS query and in the SNI field at the start of the connection. The ISP knows what you opened, not what was inside. Details in what can my ISP see.
  • Your IP address. The site sees it; HTTPS has nothing to do with that.
  • Your data inside the site. What the site does with what you submit is a policy matter.
  • Your device. Malware on the phone reads everything before it's encrypted.
WHAT THE PADLOCK DOES NOT MEANFIG. 04
"this site is honest"      no
"you will not be scammed"  no
"the owner was vetted"     no
   └─ it means the connection is
      encrypted and the domain
      is the one you asked for

What "Not secure" and the padlock icons mean

  • Padlock, or the neutral "tune" icon in recent Chrome: encrypted, certificate valid.
  • "Not secure": plain HTTP. Don't type anything into that page that you'd mind losing.
  • A red certificate warning: expired, issued for a different domain, or signed by somebody your browser doesn't trust. On a network that isn't yours, that can mean interception. Don't click through, especially for banks and email.
  • Click the padlock: it tells you who the certificate was issued to, and by whom. On your bank's site you want to see the bank's name or a known authority, not a blank.
READING THE ADDRESS BARhttps://Encrypted, certificate validpadlock or the tune iconNot securehttp://Plain HTTPtype nothing you'd mind losing!Certificate warningStop, do not click throughexpired, wrong domain or untrustedyourbank-secure-login.comEncrypted, not your bankread the address, not the icon
The icon tells you about the connection; only the address tells you who you are talking to.

How to turn on HTTPS-only mode

You can tell your browser to refuse the unencrypted version of a site outright. Chrome: Settings → Privacy and security → Security → "Always use secure connections". Firefox: Settings → Privacy & Security → "HTTPS-Only Mode". Turn it on; it closes the rare but painful cases where a link leads to http://.

ON A NETWORK YOU DO NOT TRUSTFIG. 05
your content             protected
which sites you visit    visible
a certificate warning    never ignore it
The content is what encryption already handles here; the certificate warning is the part that depends on you.

Is HTTPS enough on public Wi-Fi?

In a coffee shop, HTTPS does the heavy lifting: your content is unreadable. Three gaps are left: your DNS (the internet's phone book) queries, the network's login page, which is often plain HTTP, and apps that are less strict than your browser. What to do about them is in is public Wi-Fi safe.

TWO LAYERS, TWO JOBSFIG. 06
HTTPS   hides the content from
        everyone on the path
tunnel  hides who you are talking
        to from your ISP
   └─ neither replaces the other

HTTPS and VPN: layers, not substitutes

HTTPS encrypts content between you and the site. A VPN encrypts all of the device's traffic between you and the VPN server, including DNS and site names, and hides your IP. One without the other leaves gaps: without HTTPS the VPN server could read content; without a VPN the ISP gets the site list. Together they cover nearly everything. The DNS half of that is explained in what is DNS.

● WITHOUT A VPNYour browserDNS queryname in plain textTLS start (SNI)name in plain textPage contentencrypted by HTTPSthe ISP knows what you opened, not what was inside● WITH A VPNYour browserDNS queryTLS start (SNI)Page contentinside the tunnel: the ISP sees one connection to the VPN server
HTTPS seals the page, but the site's name leaves twice in plain text before it.

A certificate warning is the one browser message you should never click past blindly.

Prompt for an AI
Help me understand a certificate warning.

The warning text: (paste it exactly).
Site: (the domain only).
Browser: (which). Network: (home / work / public
Wi-Fi / hotel).
Have I installed anything recently that added a
certificate: (yes / no / not sure).

Say what this error means, whether it can be
harmless, and in which cases it must never be
bypassed.
Do not tell me to click through if the risk is
real given these answers.

In short

  • Padlock = encryption + verified domain. Not = honest site.
  • Read the address, not the icon. A certificate warning means you stop.
  • Turn on HTTPS-only mode.
  • The ISP still sees site names; only a VPN, or encrypted DNS plus ECH where supported, closes that.

404 VPN builds its tunnel with VLESS over TLS 1.3 and carries DNS inside it, so site names aren't visible to the network. Its WireGuard configs for Istanbul and Marseille do the same with WireGuard's own encryption, which isn't TLS. Details on the security page; get started here.