Try it yourself
Four small businesses, and what happens when a browser asks each one for its homepage.
Which site is putting its visitors at risk?
-
Encrypted, trusted, and the padlock shows. This is the target.
-
Correct behaviour. The insecure address exists but immediately sends everyone to the secure one, so nobody stays on http by accident.
-
This is the one. The site answers on http and never upgrades, so everything typed into it — names, phone numbers, the contact form — travels in the clear, and browsers mark it "Not secure" beside the address. Every modern browser now shames this in front of the visitor.
-
A free certificate is a real certificate. Browsers do not distinguish, and neither does Google. Paying for one buys you support and paperwork, not security.
Pick a line. Every one of them has an answer.
Show me the answer
http://greenfield-vets.example/ 200 OK served over http
This is the one. The site answers on http and never upgrades, so everything typed into it — names, phone numbers, the contact form — travels in the clear, and browsers mark it "Not secure" beside the address. Every modern browser now shames this in front of the visitor.
The written version
HTTPS: the padlock, and why browsers insist on it →
How to check your own site for this, what to change, and how to confirm it worked.
Now the real thing
Run this check on your own site.
The same check, plus twenty-nine others, against your actual pages. Free, no account, about a minute.