what is an SSL certificate? why your site says not secure and how to fix it
web · Oct 7, 2026 · 5 min read
an ssl certificate is a small file on your host's server that does two things: it proves the server is who it claims to be, and it enables the encrypted connection between your site and your visitors. that is the "s" in https — hypertext transfer protocol secure. without it, the traffic between the browser and the server travels in plain text, readable by anything between the two.
the name is a fossil — ssl is the old protocol, tls is the current one, and everyone still says ssl. the padlock in the address bar is its public face.
what the padlock does and does not mean
it does mean: nobody on the wire can read or alter what passes between the visitor and the site. passwords, form submissions, everything travels in an envelope.
it does not mean: the site is honest, safe, or virus-free. a phishing site can have a perfect padlock — the certificate proves the encryption, not the intentions. this is the single most misunderstood security icon on the internet, and the distinction matters: ssl is hygiene, not virtue.
"not secure" and what it costs you
when a site is served over plain http, chrome flags it "not secure" in the address bar. for a visitor that reads as "this business does not keep up". worse, forms on http pages get increasingly hostile treatment from browsers. in 2026 there is no good reason for any site — not a blog, not a portfolio, not a one-page restaurant menu — to be on http. none.
the fix, and why it is free now
for twenty years certificates cost money and were renewed by hand, which is why half the web lagged behind. then let's encrypt arrived and made certificates free and automatic: your host or your builder requests one, a machine verifies you control the domain, and the certificate renews itself every couple of months without anyone touching anything. today the honest sequence for "my site says not secure" is:
- if you are on a builder: it is a toggle in settings, or already on and you are looking at a cached page.
- if you are on your own hosting: one click in the control panel in practice, plus making sure the site's internal links use https.
- then the part everyone forgets: mixed content. if the page loads over https but an image or a script inside it still points at an http address, the padlock breaks. the fix is updating those old hardcoded links.
ssl vs "is my site secure"
ssl is the seatbelt, not the alarm system. the padlock says the trip is private; it says nothing about whether the car was built well. whether your site itself is hardened — updated dependencies, sane forms, no leaked keys — is a different question entirely, and i took it apart in is my website secure. the two get confused because they share vocabulary, but a site can be fully https and fully fragile.
one more connection worth knowing: enabling https is also a dns-adjacent operation — the certificate is issued for your domain name, so it rides on the same name-to-number system described in what is dns in simple words. move your domain carelessly and the certificate is the first thing that screams.
FAQ: the questions i actually get
does an ssl certificate cost money?
not anymore, in the overwhelming majority of cases. let's encrypt made the basic certificate free and hosts bundle it. paid certificates exist for special validation needs, not for a small-business site.
is https required for seo?
it is a confirmed ranking signal and, more practically, browsers shame its absence. the direct ranking effect is small; the trust effect on visitors is not.
how do i know my certificate is working?
the padlock, plus any of the free online checkers that grade the configuration. if the padlock is there and no warning appears on your forms, you are fine.