SSL certificates for online shops: what the padlock promises, and what it doesn't
The padlock in the address bar: proof the connection between a shopper and your site is private. It says nothing about whether the shop is honest.
- 126SSL (Secure Sockets Layer)
- A standard security technology for establishing an encrypted link between a server and a client, ensuring data transmitted remains private and secure.

- Now properly called
- TLS, though everybody still says SSL
- Shows up as
- https and a padlock; browsers flag plain http pages as not secure
- On Shopify
- Issued free and automatically for every domain you connect
- Doesn't prove
- That the business behind the site is real or trustworthy
SSL, TLS and https: one job with three names
SSL is the old name. The versions actually called SSL were retired years ago and replaced by TLS, but the name stuck. Everybody still says SSL certificate, including the people selling them.
The job hasn't changed. The certificate proves the site really is the domain it claims to be. The connection it sets up encrypts everything passing between the shopper's browser and your store: addresses, passwords, card details, the lot.
On Shopify you don't buy one. Shopify issues a certificate for every domain you connect and looks after it, and you can't swap in one from elsewhere. One less thing to forget.
Where an online shop's certificate quietly breaks
The storefront's usually fine. The trouble is everything around it that doesn't live on Shopify.
- A blog, help centre or landing page on another platform, under your domain
- Images or scripts in an old theme still loading over plain http
- Links in flows and templates still pointing at an http address or an old domain
- An email click tracking domain that never finished setting up
That last one matters more than it sounds. With dedicated click tracking in Klaviyo, every link in your emails runs through a subdomain of yours. Its help centre says Klaviyo requests and renews the certificate on current setups, though not on some older ones, and without one people clicking get a browser warning instead of your shop. Check yours shows as verified.
TLS in your inbox: the same idea protecting your email
The same technology protects email on its way between servers. Google's sender guidelines list a TLS connection as a requirement for every sender, small ones included. That part's your email platform's job. Your part is making sure every link lands on an https page you control.
One last thing. The padlock proves privacy, not honesty, and phishing sites carry padlocks too. What tells inboxes to turn away email faked in your name is DMARC, and it's worth an afternoon.
Related terms
FAQs

Do I need to buy an SSL certificate for my Shopify store?
No. Shopify issues one free for every domain you connect to your store, and you can't install one from another provider. You only need to think about certificates for things that live elsewhere under your domain, like a blog, a help centre or a landing page tool.
What's the difference between SSL and TLS?
TLS is the modern version of the same thing. The old SSL versions were retired as weaknesses turned up, and TLS replaced them, but the name SSL survived in everyday use. When anybody sells you an SSL certificate today, the connection it protects is running TLS.
Does the padlock mean a website is safe to buy from?
No. It means the connection is encrypted and the site is the domain it says it is. It doesn't vouch for the business, and fraudulent shops get certificates as easily as honest ones. For your own customers, a domain they recognise, a clear returns page and email that's authenticated as yours are better signs.
Rather we explained it on your own account?
Bring your Klaviyo account to a growth consultation. We'll walk through what this means for your numbers, in plain English, and what we'd fix first.


Half an hour with Theo, our founder.
We're all about relationships built on trust, mutual respect and a shared vision for success. If that sounds like your vibe, let's make some waves together 🌊



