A website security certificate, often called an SSL or TLS certificate, helps your browser confirm that the encrypted connection belongs to the domain in the address bar. When that proof fails, the browser warns you.
Does this affect you?
Use this when Chrome, Safari, Edge, Firefox, or another browser shows a warning such as Your connection is not private, connection not secure, or a certificate error.
What a certificate does and why warnings happen
Certificates are mostly checked automatically, but warnings deserve attention.
- A certificate authority verifies that the certificate requester controls a domain, then issues a certificate your browser can trust.
- Your browser checks that the certificate matches the exact domain, has not expired, and was issued by a trusted authority.
- Expired certificates are common and often accidental. Avoid sensitive activity until the site fixes it.
- A certificate for the wrong domain is more serious. It can be a misconfiguration, but it can also indicate interception or a fake site.
- A self-signed certificate means the site is vouching for itself without a trusted outside authority. That may be normal on internal test systems but is suspicious on public consumer sites.
When to stop and when to investigate
The context matters.
- A hotel, airport, or coffee shop Wi-Fi login page may trigger a certificate warning because its captive portal is misconfigured. That is usually about joining the network, not proof your device is infected.
- A sudden certificate warning on a bank, email, healthcare, or shopping site you use regularly should be taken seriously.
- Do not enter passwords, card numbers, or personal details through a certificate warning.
- Try the site again from a trusted network or another device before assuming it is safe.
- If the issue appears only on a work or school device, check whether your organization uses managed certificates for security monitoring.
More control
Valid certificate does not mean honest site
A certificate proves encryption for the domain shown. It does not prove the business is legitimate. Scam sites can obtain valid certificates for their own fake domains.
Read the domain along with the warning
Certificate safety and domain spelling work together. A padlock on a misspelled bank domain is still a problem.
Sources
- CISA – Understanding Web Site Certificates (2025)
- Google Chrome Help – Fix connection errors: Your connection is not private (2025)
- Mozilla Support – Your Connection Is Not Secure error message (2025)
