SSL padlock explained: what the green lock actually proves and what it doesn't
Keep seeing this misunderstood so worth saying clearly: the padlock in your browser means the connection is encrypted. that's it. it does not mean the site is legitimate, the business is real, or anyone verified who owns it.
Let's Encrypt made SSL free and automatic years ago. scammers have had valid padlocks on phishing pages since at least 2018. a padlock just means your data travels to the scam site securely.
There used to be a higher-tier cert (EV SSL) where the issuer actually verified the legal identity of the company. you'd see the company name in green in the address bar. browsers quietly removed that indicator a few years back. so even that signal is basically gone now.
HTTP with no padlock in 2026 is a red flag. HTTPS with a padlock is not a green flag. it's just table stakes.
what do you actually check before entering card details on a site you've never used?