HTTPS, the padlock, and why nobody should sell you a certificate
If someone has quoted you hundreds of dollars a year for an "SSL certificate," read this first. The padlock should simply come with your hosting.
2 min read
That little padlock in your browser's address bar means the connection between your visitor and your website is encrypted. Nobody on the coffee-shop Wi-Fi can read what they type into your contact form, and nobody can tamper with the page on the way.
Browsers now warn visitors when a site doesn't have it. Chrome labels those sites "Not secure," right next to your business name. For a local company asking people to trust them with their home, that's a bad first impression.
What a certificate actually is
To show the padlock, a website needs a certificate — a small digital file that proves the site really belongs to the domain name in the address bar. Certificates expire and need to be renewed regularly.
Why you shouldn't be paying extra for one
For years, certificates were sold as premium add-ons, sometimes for hundreds of dollars a year. Today, free and automated certificate services issue them in seconds, and any modern host can renew them without anyone lifting a finger.
The expensive "premium" certificates some hosting companies still upsell mostly add paperwork and a fancier seal image. For a local service business, they don't make visitors any safer than a standard certificate does.
What to expect from your host
- HTTPS on your site's address from day one.
- Automatic renewal, so the padlock never lapses.
- Visitors who type the plain "http://" address get sent to the secure version automatically.
- No separate line item on your bill.
At Flagstage, HTTPS is part of hosting on every plan. We issue the certificate when your domain is connected and keep it current. You will never see it as a product, because it isn't one.
Want this handled for you?
Flagstage customers send changes like these in one message and approve a preview before anything goes live.