Defense

Does the padlock mean a site is safe? The HTTPS myth

Phish Plug ResearchApril 22, 20266 min read

"Look for the padlock" is some of the most repeated — and most misunderstood — security advice. The padlock does mean something, but not what most people think. Clearing up the HTTPS padlock myth matters, because relying on it gives a false sense of safety that phishing sites exploit every day.

What the padlock actually means

The padlock indicates that the connection between your browser and the site is encrypted — no one in the middle can read or tamper with the traffic. That is genuinely useful. But encryption says nothing about who you are connected to. It protects the pipe, not the destination.

Why phishing sites show a padlock too

TLS certificates are now free and quick to obtain. So attackers get one for their lookalike domain, and the phishing page displays the same reassuring padlock as the real site. They do it deliberately: a missing padlock triggers a browser "not secure" warning, and the padlock makes a clone look legitimate.

A padlock on a phishing page is normal, not rare. Most credential traps today are served over HTTPS — the padlock has become part of the disguise.

What to check instead

  • The real domain — read the registrable name carefully. Your brand appearing somewhere in the address is not the same as being on your domain.
  • How you got there — a link in a message is far riskier than a typed address or a trusted bookmark.
  • Context — unexpected login prompts and urgency are warning signs the padlock can't address.

Even these are hard on a phone, where the full URL is truncated and a homoglyph domain can look perfect — which is why the burden can't sit entirely on users.

Because users can't reliably vet a cloaked, HTTPS-padlocked lookalike, brands close the gap by monitoring for their own clones and removing them. Phish Plug does exactly that.

The takeaway

The padlock means encrypted, not safe. Phishing sites use HTTPS precisely to look legitimate, so the padlock is no longer a trust signal. Judge the domain and the context instead — and, as a brand, don't rely on customers to do what even experts find hard on mobile.

See your brand's exposure in one pass

Run a free clone check on one domain — lookalikes surfaced, cloaking proven, evidence captured.