Does the padlock mean a site is safe? The HTTPS myth
"Look for the padlock" is some of the most repeated — and most misunderstood — security advice. The padlock does mean something, but not what most people think. Clearing up the HTTPS padlock myth matters, because relying on it gives a false sense of safety that phishing sites exploit every day.
What the padlock actually means
The padlock indicates that the connection between your browser and the site is encrypted — no one in the middle can read or tamper with the traffic. That is genuinely useful. But encryption says nothing about who you are connected to. It protects the pipe, not the destination.
Why phishing sites show a padlock too
TLS certificates are now free and quick to obtain. So attackers get one for their lookalike domain, and the phishing page displays the same reassuring padlock as the real site. They do it deliberately: a missing padlock triggers a browser "not secure" warning, and the padlock makes a clone look legitimate.
A padlock on a phishing page is normal, not rare. Most credential traps today are served over HTTPS — the padlock has become part of the disguise.
What to check instead
- The real domain — read the registrable name carefully. Your brand appearing somewhere in the address is not the same as being on your domain.
- How you got there — a link in a message is far riskier than a typed address or a trusted bookmark.
- Context — unexpected login prompts and urgency are warning signs the padlock can't address.
Even these are hard on a phone, where the full URL is truncated and a homoglyph domain can look perfect — which is why the burden can't sit entirely on users.
Because users can't reliably vet a cloaked, HTTPS-padlocked lookalike, brands close the gap by monitoring for their own clones and removing them. Phish Plug does exactly that.
The takeaway
The padlock means encrypted, not safe. Phishing sites use HTTPS precisely to look legitimate, so the padlock is no longer a trust signal. Judge the domain and the context instead — and, as a brand, don't rely on customers to do what even experts find hard on mobile.
Keep reading
Related articles
Account takeover (ATO): how one phish becomes many
Account takeover is where phishing pays off. How stolen credentials turn into fraud, why reuse spreads the damage, and how to break the chain.
Read article Threats · 7 minCredential stuffing vs. brute force: know the difference
Both attack logins, but in opposite ways. How credential stuffing reuses stolen passwords at scale, how brute force differs, and what stops each.
Read article Detection · 7 minDark web monitoring for leaked credentials
Leaked passwords fuel account takeover. What dark web monitoring can and can't do, how to act on a hit, and where it fits in a brand-protection programme.
Read articleSee your brand's exposure in one pass
Run a free clone check on one domain — lookalikes surfaced, cloaking proven, evidence captured.