SSL, TLS, HTTPS — what does it all actually mean? This guide cuts through the jargon and explains why HTTPS matters for every website.
April 2026
By Open Domains Team· 8 min read
ssl https security certificates
If you've ever clicked the padlock icon in your browser's address bar and seen a bunch of technical-sounding terms, you've encountered SSL. But what does it actually mean, why does it matter, and do you really need it? (Spoiler: yes, every website needs HTTPS in 2026.)
SSL vs. TLS — What's the Difference?
SSL (Secure Sockets Layer) is an older encryption protocol, now replaced by TLS (Transport Layer Security). In practice, people still say "SSL" to mean what's technically TLS. When someone says "SSL certificate," they mean a TLS certificate. Same thing — different name.
The current standard is TLS 1.3 (released 2018), which is faster and more secure than all previous versions. If you're using a modern hosting platform or Cloudflare, you're already using TLS 1.3.
What Does SSL Actually Do?
An SSL/TLS certificate does three things:
▸Encryption: Data transmitted between the user's browser and your server is encrypted. Nobody intercepting the traffic can read it.
▸Authentication: The certificate proves that the server really belongs to the domain it claims. This prevents "man in the middle" attacks where someone impersonates your server.
▸Integrity: Data can't be tampered with in transit without detection.
Note: Without HTTPS, any network between your user and your server — their ISP, a coffee shop Wi-Fi, a mobile carrier — can read and modify the data. This is particularly serious for login forms, payment details, and personal information.
Types of SSL Certificates
▸Domain Validated (DV): Proves you control the domain. Issued in minutes. The green padlock. Used by 99% of websites. What Let's Encrypt gives you.
▸Organisation Validated (OV): Verifies your organisation's identity. Takes days. Better for business sites.
▸Extended Validation (EV): Strict verification. Previously showed the company name in green in browsers — most browsers have removed this UI distinction now.
▸Wildcard: Covers all subdomains (*.yourdomain.com). More expensive from commercial CAs, but free with Let's Encrypt via DNS challenge.
▸Multi-domain (SAN): Covers multiple different domain names in one certificate.
Free SSL with Let's Encrypt
Before 2016, SSL certificates cost £50-200/year. Let's Encrypt changed everything — it's a free, automated, open Certificate Authority that's now trusted by all browsers. Most hosting platforms (Netlify, Vercel, Cloudflare Pages) automatically provision Let's Encrypt certificates for your custom domains.
Get Let's Encrypt cert manually (Certbot)
# Install Certbot
sudo apt install certbot python3-certbot-nginx
# Get certificate
sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com
# Certificates auto-renew every 90 days
Why Every Site Needs HTTPS in 2026
▸Google ranking: HTTPS has been a ranking signal since 2014. HTTP sites rank lower.
▸Browser warnings: Chrome marks HTTP sites as "Not Secure" — users will leave
▸User trust: The padlock icon signals safety. Its absence destroys credibility.
▸Modern web features: Service workers, geolocation, camera access — all require HTTPS
▸HTTP/2 and HTTP/3: These faster protocols require HTTPS in practice
💡 Tip: With Let's Encrypt and platforms like Cloudflare handling certificate management automatically, there's no reason any website should be running on HTTP in 2026. It's free and automatic.