Does HTTPS Mean a Website Is Safe?
The padlock and HTTPS mean your connection is encrypted, not that the website is honest. What HTTPS really protects, why phishing sites use it, and what to check instead.

For years people were told to "look for the padlock" before entering details online. That advice is now misleading. Most websites, including most phishing sites, use HTTPS and show a padlock. It tells you the connection is private, not that the person on the other end is trustworthy.
What HTTPS actually means
| HTTPS does | HTTPS does not |
|---|---|
| Encrypt data between you and the site | Prove the site belongs to the brand it shows |
| Stop others on the network reading it easily | Mean the site is honest or safe |
| Confirm you reached the domain in the address bar | Check whether that domain is a lookalike |
Why phishing sites use it
Encryption certificates are available free and automatically for almost any domain. Criminals get them for their lookalike domains, so the padlock appears on fake bank and shopping pages too. Some people even trust those pages more because of it.
A padlock on examplebank-verify[.]com only means you have a private connection to a criminal's website.
What to check instead
- The domain. Is it the organization's real domain? See how to read a URL.
- How you got there. Did you type it or use a bookmark, or follow a link from a message?
- Your password manager. If it does not offer to fill in, suspect a fake. See password managers as a phishing alarm.
- Browser warnings. Never click past a red "deceptive site" warning. See browser protections.
When HTTPS still matters
Never enter passwords or payment details on a page without HTTPS. It is a minimum, not a guarantee.
Unsure about a site? Paste its address into CyberWatch AI Scan for a free check.
For more, read our phishing guide.
Frequently asked questions
What does HTTPS protect?
It encrypts the connection between your browser and the website, so others on the network cannot easily read or change what you send.
Why do phishing sites have padlocks?
Encryption certificates are easy and often free to obtain for any domain, including domains registered by criminals.
Should I avoid sites without HTTPS?
Yes, never enter passwords or payment details on a site without HTTPS. But HTTPS alone is not enough to trust a site.
Sources
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Online Shopping, US Federal Trade Commission
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre


