Why the green padlock (HTTPS) does not mean a website is safe

Last updated:

Frequently asked questions

Does HTTPS or a green padlock icon prove that a website is safe?

No. The HTTPS protocol and padlock icon only prove that communication between your browser and the server is encrypted. It prevents eavesdropping on your network, but says nothing about the honesty or legitimacy of the website owner.

Why do most scam websites display a valid padlock today?

SSL certificates are now automated and issued free of charge in seconds. Any malicious actor can register a fraudulent domain name and instantly obtain a valid SSL certificate.

What should you check instead of relying on the padlock?

Check the exact spelling of the domain name (look out for character swaps, risky extensions like .top or .info), examine legal business disclosures, domain age, and artificial urgency tactics.

How have modern web browsers updated the padlock indicator?

Due to widespread user confusion, Google Chrome and other major browsers removed the green highlight and replaced the padlock with a neutral tune icon to prevent users from mistaking encryption for verified trust.

More guides
Protect your browser

Do not rely on the padlock icon to judge website legitimacy. Resku evaluates real domain reputation, underlying code, and fraud traps before you type.

Join the waitlist
← Back to all guides