Front Step Sites

What SSL is and why your site needs the padlock

Updated September 26, 2026

Someone says your website needs SSL and a padlock, but you are not sure what you are supposed to buy or check. Is this an expensive extra or a normal part of running a business website? You need working HTTPS, and you should expect your provider to explain how certificates and renewals are handled.

Understand the connection in plain English

When a visitor opens your website, their browser exchanges information with the server that provides the page. HTTPS protects that connection using encryption. The familiar term SSL is still used in sales conversations, although modern secure connections use TLS, its successor.

A certificate helps the browser verify the site it is connecting to. It must be valid for the address being visited and work with the site's setup. Mozilla's TLS overview explains the relationship between the certificate and the secure connection.

For your business, the practical requirement is simple: customers should be able to open your pages and submit ordinary inquiries without a connection warning. You do not need to learn certificate formats to ask your website provider to make that work.

The certificate, domain, and hosting are related but different pieces. Registering an address alone does not prove that the website at that address has been set up correctly. Our guide to website hosting in plain English explains where the site itself lives.

Know what the browser symbol does and does not mean

The phrase "needs the padlock" is familiar shorthand, but the literal icon is not universal. Chrome replaced its lock icon with a site controls icon, as explained in the Chromium announcement. Other browsers may present connection information differently.

Look for a working HTTPS address and check the browser's connection information rather than judging the site by one symbol. A missing traditional lock icon does not by itself mean your site is broken. A warning about the connection deserves investigation.

A secure connection also does not prove that the business behind a website is honest. An encrypted connection can lead to an untrustworthy site. Do not advertise SSL as proof that your company has passed a background check or that every part of the business is secure.

Your customers still need the ordinary signs of a trustworthy local company: accurate contact details, clear services, and real evidence of work. HTTPS supports the visit, but it cannot replace those basics.

Ask for certificates and renewal to be included

For an ordinary small business website, ask for HTTPS setup and certificate renewal to be included in the website or hosting service. This is a reasonable requirement to put in writing before choosing a provider. Do not accept vague wording that leaves you unsure who fixes an expired certificate.

Free certificates are available through services such as Let's Encrypt. The certificate being free does not mean every provider's installation, hosting, or support work is free. Ask what any quoted charge actually covers rather than assuming you must buy an expensive certificate for a basic brochure site.

Useful questions for your provider include:

  • Is HTTPS configured for the website addresses customers actually use?
  • Who manages certificate renewal?
  • How will a failed renewal or connection problem be noticed?
  • Who should I contact if a visitor reports a warning?

Avoid relying on a one-time installation with no clear renewal responsibility. You want an ongoing arrangement that someone owns. Keep the support contact with your domain and hosting records so the problem does not become a search through old emails.

Check the website from the customer's side

Type your business address into a browser and open the homepage, service pages, and contact page. Confirm that they load using HTTPS without warnings. Test the addresses you actually print or link to, including a www version if you use one.

Also try an old link that begins with HTTP. Ask your provider to make that address lead safely to the secure version. A visitor should not have to know which variation to type before reaching the right page.

Check forms and embedded services as well. A secure outer page does not prove that every connected tool is configured correctly. Ask the maintainer to review the form submission path and any insecure resources reported by the browser.

Use the guide to contact forms that get filled out to test the entire inquiry journey. Send a harmless test message and verify delivery. The combination of secure loading and a working submission is more useful than a certificate screenshot alone.

Respond to warnings without asking customers to ignore them

If a customer reports a warning, record the page address and the message they saw. Ask your provider to investigate the cause. It may involve an expired certificate, an address mismatch, or another configuration issue, so avoid guessing from a vague report.

Do not tell customers to bypass a warning to send their information. Give them a working phone number or another appropriate contact route while the site is checked. Keep the message practical and avoid collecting sensitive information through an uncertain path.

Once the provider reports a fix, reopen the affected address and test the contact page again. Check the page the customer used, not just a different homepage address. Ask what failed and who will watch for a repeat.

HTTPS protects information during the connection; it does not replace careful handling after a form arrives. Limit what you collect and who can access it. Our guide to privacy policies for business websites offers general pointers for describing your information practices.

Frequently asked questions

Does a simple website need HTTPS if it takes no payments?

Yes, use HTTPS even for a basic service website. It provides a protected connection for browsing and any ordinary inquiries you collect. Payment processing is not the only reason to configure it correctly.

Do I have to buy a special certificate to look trustworthy?

An ordinary business site needs a valid, correctly configured certificate, not an unexplained premium label. Ask the provider to justify any extra service in terms you understand. Trust also depends on accurate business information and honest content.

Does HTTPS protect messages after they reach my inbox?

It protects the relevant web connection, not every later handling step. Your email account, form service, and staff access need their own care. Avoid collecting information you do not need through a general inquiry form.

The short version

Ask for working HTTPS and a clear certificate renewal arrangement, not a particular browser icon. Test your real pages and forms, and have warnings investigated rather than bypassed. If you are comparing website providers, Front Step Sites offers websites for $99 a year with the domain included and no setup fee.