Your IP address:
Provider:
...

HTTP vs HTTPS: what a secure connection protects

HTTP defines requests and responses between a client and a web server. HTTPS uses the same web semantics over a protected connection: data is encrypted, and the client checks that the server is authorised for the name in the address bar. This protects the exchange in transit, not the honesty of the site owner.

What HTTPS changes

With ordinary HTTP, another party on the network path may be able to read or alter content. HTTPS negotiates a secure channel and checks a certificate for the requested host name. Modern sites can use TLS over TCP for HTTP/1.1 or HTTP/2, or QUIC for HTTP/3. HTTPS therefore is not tied to just one HTTP version. It protects the confidentiality and integrity of data between the browser and the endpoint of that secured connection.

Some facts about a connection can remain visible to the network, such as the remote IP address and approximate amount of data transferred. Proxies, enterprise inspection and third-party resources can also change where trust boundaries lie. HTTPS does not make every action private, nor does it replace account security.

What a certificate proves

The browser checks that the certificate covers the requested name, has an acceptable trust chain and meets its security policy. A warning about a wrong host name, expiry or an untrusted issuer should not be solved by turning verification off. Read the precise error: an incorrect device clock can also make dates appear invalid.

A valid certificate for example.org connects the browser to that name; it does not establish that the site sells genuine goods or tells the truth. A phishing site can obtain a valid certificate for its own misleading domain. Check the entire host name before entering a password, especially after following a message or advertisement.

What users and owners should do

Users should avoid sending passwords or payment details over HTTP. If HTTPS shows a warning, do not bypass it for sensitive actions. Owners should redirect HTTP requests to HTTPS, maintain certificates for every used host name, and avoid loading sensitive page resources over HTTP. After a migration, test forms, embedded resources and canonical URLs as well as the home page.

RFC 9110 defines HTTP and HTTPS schemes and shared semantics. The site information tool can show technical details, but those details do not rate the owner’s honesty. A separate guide explains how to interpret TLS certificate errors.