SSL Certificates in Plain English: What They Do and How to Get One
Learn what an SSL/TLS certificate is, why the padlock matters, the types available, how to install one and how to fix common HTTPS errors on your site.

If you have ever seen a padlock beside a web address, or a browser warning that a site is "not secure", you have met SSL certificates. They are one of the most important parts of a modern website, yet the terminology confuses many beginners. This guide explains what a certificate does, the kinds you can get and how to install one without fuss.
What an SSL certificate actually is
An SSL certificate is a small digital file that lets a browser confirm it is talking to the real server for your domain, and lets the two of them communicate in a private, encrypted way. The result is HTTPS, the secure version of HTTP.
A technical note: the old SSL protocol was replaced years ago by TLS. People still say "SSL certificate" out of habit, and hosts use the term in their marketing, but the technology in use today is TLS. The two names refer to the same kind of certificate in everyday conversation.
What it protects
Think of an ordinary connection as a postcard: anyone handling it along the way can read it. HTTPS puts the message in a sealed envelope. With a valid certificate:
- Encryption: data such as passwords, form entries and payment details cannot be read by someone intercepting the connection, for example on public Wi-Fi.
- Integrity: the content cannot be quietly changed in transit, such as having extra ads inserted into your pages.
- Identity: the browser verifies that the certificate was issued for your domain by a trusted authority.
It is important to understand the limits. A certificate does not mean a site is honest or free of malware; it only means the connection is private and the domain is verified. A scam site can have a padlock too.
Why every site needs one
- Browsers mark sites without HTTPS as not secure, which makes visitors nervous.
- Any page with a login, contact form or checkout should be encrypted. Many modern browser features also require HTTPS.
- Search engines treat HTTPS as a lightweight ranking signal.
- Payment providers and advertising networks generally expect secure sites.
- It protects your own admin login from being captured.
Types of certificates
Certificates differ mainly in how much checking the issuer does, and in how many domains they cover.
| Type | What is verified | Typical use |
|---|---|---|
| Domain Validated (DV) | Only that you control the domain | Blogs, small business sites, most websites |
| Organization Validated (OV) | Domain control plus basic details about the organization | Company sites that want extra identity checking |
| Extended Validation (EV) | Domain plus a stricter check of the legal entity | Large organizations; browsers no longer show it very differently |
| Coverage | Meaning |
|---|---|
| Single domain | Covers one hostname, such as www.example.com |
| Wildcard | Covers a domain and all its subdomains at one level |
| Multi-domain (SAN) | Covers several different domain names in one certificate |
For most personal and small business websites, a DV certificate is entirely adequate. The encryption strength does not depend on the type; the difference lies in the identity checks.
Free or paid?
Free certificates are issued by non-profit authorities and are trusted by all major browsers. They are normally valid for a short period and renew automatically, which most hosts handle for you. Paid certificates may add warranties, support, organization validation or longer management features. If your host offers free automatic SSL, that is a good default for small sites. A host that charges extra for a basic certificate deserves a second look.
How to get and install one
The easy route: let your host do it
- Log in to your hosting control panel.
- Look for a section called SSL, TLS or Security, depending on the panel.
- Enable the free certificate for your domain and the www version.
- Wait a few minutes for it to be issued and check that the site opens with https.
Redirect everything to HTTPS
Having a certificate is not enough; visitors must be sent to the secure version. Add a site-wide redirect from http to https, either through a setting in your panel, a plugin or your server configuration. Then update your site address in your CMS settings, and update your sitemap, canonical tags and analytics to use the https address.
Buying a certificate separately
If you need a paid one, the process is: generate a certificate signing request on your server or panel, give it to the authority, prove you control the domain (usually by email, a DNS record or a file), then install the issued certificate and any intermediate files. Many hosts will do the installation for you.
Common problems and fixes
- Mixed content warning: the page loads over https but some images or scripts still use http. Update those links to https.
- Certificate expired: certificates have an end date. If automatic renewal failed, renew it in your panel or contact your host.
- Name mismatch: the certificate does not cover the exact address visited, for example it covers example.com but not www.example.com. Reissue it with both names.
- Redirect loop: an over-eager setup between a CDN, plugin and server can send pages back and forth. Keep a single place responsible for the redirect.
- Untrusted issuer: usually a missing intermediate certificate or a self-signed certificate. Install the full chain.
Frequently asked questions
Does HTTPS slow down my website?
The overhead is tiny on modern servers, and HTTPS enables newer protocols such as HTTP/2 that can actually improve loading.
Do I need a certificate if I do not sell anything?
Yes. Even a simple blog has a login page and contact forms, and visitors will see browser warnings without HTTPS.
What happens when a certificate expires?
Browsers show a full-page warning and many visitors will leave. Renew it quickly and the warning disappears.
Is an EV certificate safer than a free one?
The encryption is the same. EV adds stricter identity checks on the organization, which matters less to most visitors today than a working, properly configured HTTPS site.
Conclusion
An SSL certificate is a basic requirement, not a luxury. It encrypts the connection, confirms your domain and removes the warnings that scare visitors away. For most sites, a free automatic certificate from your host is enough: enable it, redirect all traffic to HTTPS, fix any mixed content and keep an eye on renewals. Once that is done, you can mostly forget about it.


