SSL certificate.

In a nutshell

An SSL certificate is a digital certificate that verifies that a website belongs to its domain and enables the encrypted HTTPS connection between the browser and the server.

As of October 5, 2026 · Dustin Tatarowicz, marschfahrt

An SSL certificate ensures that your website is accessible via HTTPS—that is, encrypted. This protects anything a visitor enters—from contact forms to login credentials—from being read or altered as it travels to the server. According to Google Help, if a secure connection is missing, Chrome may display the message “Not secure” next to the address. For a business that receives inquiries online, this costs trust before anyone even reads the first sentence.

How an SSL Certificate Works

The name is historical; the technology is now called TLS. SSL was the original encryption protocol. In June 2015, the Internet Engineering Task Force classified SSL 3.0 as insufficiently secure in RFC 7568 and prohibited its use. HTTPS now runs on Transport Layer Security, currently in version 1.3 as defined in RFC 8446 from August 2018.

When someone visits your site, the server presents its certificate. The browser checks whether it comes from a recognized certificate authority, is still valid, and matches the domain being accessed. One free certificate authority is Let's Encrypt. According to Let's Encrypt, anyone who owns a domain name can obtain certificates there for free. By default, they are valid for 90 days; automatic renewal every 60 days is recommended.

What Your Business Should Keep in Mind

Ask your hosting provider about automatic certificates before you pay extra. According to its FAQ, Let's Encrypt only offers domain-validated certificates. That's sufficient for an encrypted connection on a standard company website.

Permanently redirect every HTTP address to HTTPS. According to Search Central, Google treats the switch from HTTP to HTTPS as a website migration with changed URLs. To do this, set up the certificate on the server and redirect all old addresses. Our article “SEO Basics That Are Most Often Overlooked When Building a Website” highlights other common oversights.

Be sure to check subdomains and secondary domains as well. A certificate is only valid for the names for which it was issued. In projects, we often see that the main domain works fine, but an older secondary domain listed on a business card triggers a warning.

Think of HTTPS as a foundation, not as a ranking factor. In 2014, Google announced that it would use HTTPS as a ranking signal—at the time, explicitly describing it as a very weak signal that affected less than 1% of search queries and carried less weight than high-quality content. In its current guidelines on user experience, Google continues to ask whether your pages are served securely. Learn more under SEO.

Frequently Asked Questions About SSL Certificates

What happens when the certificate expires? The browser can no longer verify that the connection is secure and will warn your visitors before they see the page. That's why you should check to see if your hosting provider automatically renews it.

Do I need HTTPS even if I don't have a store or a login? Yes. Personal data is transmitted even through a contact form. According to Google Help, if users have enabled the "Always use encrypted connections" option in Chrome, Chrome will display a warning for every website that doesn't use HTTPS.

How can I tell if my website is secure? Click the icon to the left of the address in your browser. According to Google Help, Chrome shows whether the connection is secure.

If you want to redesign or migrate your website, we'll also take care of the certificate and redirects as part of the web design process.

Is your browser warning you about your own website? We'll switch to HTTPS and set up the redirects properly.

Web Design →
← All terms in the glossary