Does a Padlock Mean a Website Is Safe? What HTTPS Isn't
- website-scam
- https
- fake-online-store
- scam-alert
Disclaimer: This post is for informational purposes only and does not constitute legal or financial advice. If you believe you have been targeted, contact your bank and local authorities immediately.
You are about to pay a site you have never used before. The address bar shows a padlock, and that padlock feels like permission to continue. It answers a far narrower question than most people think, and scammers have known that for years.
Does a padlock icon mean a website is safe?
No. The padlock means one thing: the connection between your browser and that server is encrypted, and the certificate presented matches the domain shown in the address bar. Nobody sitting on the coffee-shop Wi-Fi can read your card number in transit.
That is a statement about the pipe, not about the person at the other end of it. A criminal running a fake storefront gets exactly the same padlock you see on your bank's site. Encryption protects your data on its way to them. It does not stop them from being a thief.
The uncomfortable version: the padlock confirms your card details will reach the fraudster securely.
Example scenario
Here's a realistic composite scenario based on patterns reported to Action Fraud, the FTC and r/Scams:
I found the boots through an Instagram ad — half price, and the brand's name in the URL. The site looked right: proper product photos, size guide, a padlock next to the address. I checked for the padlock because that is what I had always been told to look for, and it was there. I paid with my debit card. The confirmation email came from a Gmail address, the tracking number never worked, and two weeks later the site was gone.
This is a realistic example built from common reports — not a single real person's story.
The detail that matters is that nothing about the padlock was fake. It was a genuine, valid certificate. It was just a certificate for the scammer's domain.
How This Scam Works
A certificate proves control of a domain, and nothing more. When someone registers a new domain, they can obtain a free certificate for it within minutes from an automated authority. The check is mechanical: can you prove you control this domain? Upload a file, or answer a DNS challenge, and the certificate is issued. No human reviews who you are, whether your business exists, or whether you intend to ship anything.
That level of validation is called domain validation, and it is the overwhelming majority of certificates on the web. It exists because encryption everywhere is genuinely good for everyone, including scam victims — an encrypted phishing page is not more dangerous than an unencrypted one. The problem was never that criminals can get certificates. The problem is that a generation of security advice told people the padlock meant "trustworthy", and that advice was never accurate.
Browser makers have quietly conceded the point. The green company-name bar for expensive extended-validation certificates was removed from Chrome and Firefox in 2019, after research showed users largely did not notice it and did not change their behaviour when it disappeared. Chrome went further in version 117 and replaced the padlock itself with a neutral settings-style icon, specifically because the padlock was so widely misread as a badge of legitimacy.
So the padlock has been demoted by the people who invented it. The advice to "look for the padlock" outlived the reason for it.
What replaces it is duller and more effective: read the domain name, and check the seller.
There are three tiers of certificate, and the difference is invisible where it counts. Domain-validated certificates check control of the domain only. Organisation-validated certificates involve some checking of the company behind it. Extended validation applies the strictest vetting of a legal entity. A shopper cannot tell them apart at a glance any more, because browsers deliberately stopped surfacing the distinction — all three render as the same neutral icon. The tier that requires the least proof is also the cheapest, the fastest and by far the most common, so it is the one a fraudulent store will hold.
The other half of the trick is the domain itself. Attackers register names that survive a quick glance: a digit standing in for a letter, an extra hyphen, a plausible new suffix like .shop or .store, or the real brand pushed into a subdomain where it looks like the site you wanted. Some go further and use characters from other alphabets that render almost identically to Latin ones, so two domains can look the same and be entirely different addresses. Browsers defend against the worst of these by displaying the raw encoded form, but the simpler tricks — hyphens, digits, extra words — need no special characters at all and defeat a hurried reader every time.
Put those together and the address bar offers exactly one reliable signal: the registrable domain, the bit immediately before the first slash. Everything else in that bar, padlock included, can be controlled by whoever registered the name.
Who Is Being Targeted
Anyone buying from a site they reached through an advert rather than by typing the address themselves. Social-media shopping ads are the dominant path — a scroll, a discount, a checkout, all inside a few minutes. The pattern hits hardest on people who were taught exactly one website-safety rule, which is the padlock rule: older shoppers, teenagers spending their own money for the first time, and anyone hurrying to buy a sold-out item.
The same misunderstanding drives phishing losses. Both the FTC's guidance at consumer.ftc.gov and CISA's phishing material at cisa.gov make the same point: the giveaway is the sender and the address, not the presence of encryption. Scamwatch tracks the shopping version of this under website scams at scamwatch.gov.au, where fake stores and lookalike retail domains are a standing category rather than a novelty.
Marketplace and rental listings work the same way. A convincing payment page on a lookalike domain, complete with padlock, collects a deposit for a property or a car that was never available.
Red Flags to Watch For
🚩 The domain is nearly right, not exactly right. paypa1-secure.com, myer-outlet.shop, or the real brand buried in a subdomain like nike.com.checkout-verify.top. The part that matters is the text immediately before the final slash — read it right to left.
🚩 The site was reached through an ad or a message, never by you typing the address. That is the single strongest predictor in the whole list.
🚩 Payment steers away from cards. Bank transfer, crypto, or a request for gift cards removes your chargeback rights, which is the entire point of asking.
🚩 Contact details are thin or fake. A Gmail address, a contact form and nothing else — no company number, no registered address, no landline.
🚩 Prices are implausible across the whole catalogue. One clearance item is a sale. Every item at seventy percent off is a lure.
🚩 The brand's own site does not link to it. A genuine outlet is reachable from the official domain. A "brand outlet" that exists only in an ad is not an outlet.
What to Do Before You Click, Reply, or Pay
- Read the domain out loud, right to left. Find the last dot before the first slash. That is the real site. Everything to the left of it can be anything the scammer wants, including a perfect copy of a brand name.
- Paste the link into our free scam checker or the scam website checker before you enter any details. Lookalike domains, recently registered domains and known-bad links surface immediately, and nothing you paste leaves your device except the extracted indicators.
- Check the address a second way. Search the brand name and go to the official site directly, then look for the offer there. If the deal is real, it exists on the domain you already trust.
- Look at the age of the domain and the quality of the contact details. A retailer that appeared weeks ago with no company registration is not a retailer. Our guide on whether a website is legit walks through the checks in order.
- Pay with a credit or debit card. Card payments carry chargeback rights that a bank transfer does not. If a site will not take a card, that is the answer.
What to Do If You've Already Been Affected
- Call your bank now and say the word "fraud". Ask about a chargeback for a card payment or a recall for a transfer. Speed matters more than paperwork.
- Change the password for that site and anywhere you reused it. A fake checkout harvests the password as happily as the card number.
- Work through have I been scammed for the ordered recovery steps, including what to watch for on your statements over the following weeks.
- Watch for the follow-up approach. People who lost money to a fake store are contacted again later by someone offering to recover it for a fee. Recovery fraud is a second, separate scam aimed at the same person.
- Report it, using the channels below. Reports are how these domains get taken down for the next person.
Where to Report
- 🇦🇺 Australia: Scamwatch, and the Australian Cyber Security Centre at cyber.gov.au
- 🇺🇸 USA: FTC ReportFraud
- 🇬🇧 UK: Action Fraud
- 🌐 International: Global Scam Reporting Directory
You can also add the domain to our community database through scam reports, which feeds the checker other people use.
Frequently Asked Questions
Is a site without a padlock automatically dangerous? It is a bad sign for anywhere you would enter a password or card number, and modern browsers now warn you. But the absence of a padlock is far rarer than a fraudulent site that has one.
Can a scammer really get a valid certificate that easily? Yes. Domain-validated certificates are free, automated and issued in minutes to whoever demonstrates control of the domain. That is by design, and it is why the certificate cannot vouch for the operator.
Why did Chrome remove the padlock icon? Because it was consistently misread. Users treated it as "this site is safe" rather than "this connection is encrypted", so it was replaced with a neutral icon that invites you to check site settings instead of implying a verdict.
Does the certificate ever tell me who owns a site? Occasionally. Organisation-validated and extended-validation certificates do name a vetted legal entity, and you can still view that under the site's certificate details. They are a small minority, and browsers no longer display the name prominently.
What about the green padlock I remember? That was the extended-validation indicator, retired from Chrome and Firefox in 2019. Nothing replaced it, because the evidence showed it was not changing what people did.
If encryption does not prove safety, is HTTPS pointless? Not at all. It stops interception and tampering on the network, which is a real and common attack. It simply answers a different question from "should I trust this seller".
Is a padlock enough for reading, as opposed to buying? For reading a news article, the risk is low either way. The moment a page asks for a password, a card, or a document, the domain becomes the thing to check.
Related Scam Checker pages
- Scam website checker — paste a store or checkout URL and get a verdict on the domain
- Check a scam link — for links arriving by message, email or ad
- Is this website legit? — the full manual checklist, in order
The padlock tells you the road is safe. It says nothing about the address you are driving to. If you are unsure about a site, paste it into our free scam checker before you enter anything.