Blog/Phishing

Does HTTPS Mean a Website Is Safe?

The padlock and HTTPS mean your connection is encrypted, not that the website is honest. What HTTPS really protects, why phishing sites use it, and what to check instead.

CyberWatch AI1 October 2026 · 2 min read
An open laptop showing a web page with photos

For years people were told to "look for the padlock" before entering details online. That advice is now misleading. Most websites, including most phishing sites, use HTTPS and show a padlock. It tells you the connection is private, not that the person on the other end is trustworthy.

What HTTPS actually means

HTTPS doesHTTPS does not
Encrypt data between you and the siteProve the site belongs to the brand it shows
Stop others on the network reading it easilyMean the site is honest or safe
Confirm you reached the domain in the address barCheck whether that domain is a lookalike

Why phishing sites use it

Encryption certificates are available free and automatically for almost any domain. Criminals get them for their lookalike domains, so the padlock appears on fake bank and shopping pages too. Some people even trust those pages more because of it.

A padlock on examplebank-verify[.]com only means you have a private connection to a criminal's website.

What to check instead

  1. The domain. Is it the organization's real domain? See how to read a URL.
  2. How you got there. Did you type it or use a bookmark, or follow a link from a message?
  3. Your password manager. If it does not offer to fill in, suspect a fake. See password managers as a phishing alarm.
  4. Browser warnings. Never click past a red "deceptive site" warning. See browser protections.

When HTTPS still matters

Never enter passwords or payment details on a page without HTTPS. It is a minimum, not a guarantee.

Unsure about a site? Paste its address into CyberWatch AI Scan for a free check.

For more, read our phishing guide.

Frequently asked questions

What does HTTPS protect?

It encrypts the connection between your browser and the website, so others on the network cannot easily read or change what you send.

Why do phishing sites have padlocks?

Encryption certificates are easy and often free to obtain for any domain, including domains registered by criminals.

Should I avoid sites without HTTPS?

Yes, never enter passwords or payment details on a site without HTTPS. But HTTPS alone is not enough to trust a site.

Sources

  1. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  2. Online Shopping, US Federal Trade Commission
  3. Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.