Home / Blog / SSL certificates in plain English

SSL certificates in plain English

Hosting
Browser address bar showing a secure lock and Connection is secure with a valid certificate

That little lock in the browser means the link between the visitor and your site is encrypted. Other people on the network should not be able to read form data in transit. For a business site in 2026, HTTPS with a valid certificate should be on. Full stop.

What SSL/TLS actually does

When someone visits https://yourdomain.com, the browser and server set up encryption. Visitors get a check that they reached the real server. Data in transit is harder to snoop on. It does not magically make your business honest. It does not make your site free of malware. It does not make your inbox safe after the form arrives. Those are separate problems.

Why browsers make a fuss

Modern browsers label plain HTTP sites “Not secure.” That banner scares people who are typing phone numbers and emails. Browsers have pushed harder every year. Customers may not know what TLS means. They know red warning text looks like a scam.

Search engines also prefer HTTPS as a baseline. It is not a magic ranking rocket. Running plain HTTP is still an unforced error.

Certificates are not magic

A certificate is issued for your domain by a certificate authority. Let's Encrypt and commercial CAs both issue them. They expire. Someone has to renew them. On well-run hosting, renewal is automatic. On neglected servers, certificates expire on a Tuesday and your phone starts ringing.

Common mishaps:

  • Certificate covers www but not the bare domain (or the reverse)
  • Old links still point to http:// and bounce oddly
  • Mixed content: page is HTTPS but images or scripts load over HTTP, so the browser blocks pieces
  • Someone installed a cert on the wrong server during a move

What customers should never see

  • “Your connection is not private” screens
  • Certificate name mismatch
  • Expired certificate warnings
  • Forms that still submit to http:// addresses

Any of these will kill online lead flow until fixed. Often faster than a redesign talk.

SSL is needed, not enough

Encryption in transit does not replace:

  • Strong account passwords and limited admin access
  • Keeping software updated if you use a CMS
  • Sensible form spam handling
  • Backups and a restore plan
  • Care about what customer data you collect and store

Think of HTTPS like seatbelts. Required. Not a full safety program.

How we handle it

Sites we host run on HTTPS with certificates managed as part of hosting. You should not be uploading cert files or racing expiration calendars. If you move to us, we map the domains so the lock works for the addresses people type.

If your current site throws security warnings, treat it like a broken phone line. Fix it before debating button colors. For broader hosting context, see What web hosting means for a small business.

Contact

Want to talk about a project?