What is SSL? What does SSL do on a website and in email?
SSL is the common name for the security protocol that encrypts data travelling between two parties over the internet. The protocol in use today is actually called TLS; the name "SSL" lives on out of habit. The same technology is used both on websites and in email, but what it protects and who sets it up are different.
In brief
- SSL (now properly called TLS) encrypts the connection between two parties.
- On a website, it protects the information a visitor enters and verifies the domain name.
- In email, it protects the link between your device and the mail server; it is not end-to-end encryption.
- The padlock icon does not guarantee that a site is trustworthy.
On this page
Understanding SSL in three steps
-
SSL on a website: https and the padlock icon
The address of a site with SSL starts with https://, and the browser shows a padlock (or a similar security) icon in the address bar. SSL encrypts the data travelling between the visitor and the site (form details, passwords, card details); anyone who intercepts it cannot read it. The certificate also verifies that the site really belongs to that domain name. On sites without SSL, browsers show a warning such as "Not secure"; if the certificate expires, a warning appears when the site is opened.
: Enlarge -
SSL in email: between your device and the mail server
In email, SSL encrypts the connection between your email program (Outlook, or the Mail or Gmail app on your phone) and the mail server. This means your password and messages do not travel in the clear over the network, especially on public Wi-Fi networks in places such as cafés and hotels. With SSL turned off or on an unencrypted connection, your password is sent as plain text and can be read by someone on the network. In your email program, make sure SSL/TLS or STARTTLS is selected in the account settings.
: Enlarge -
An important distinction: what does SSL not protect?
- In email: SSL only protects the link between your own device and your own mail server. It does not mean the message is encrypted end to end all the way to the recipient; transfer between servers is a separate matter. If the content must be readable only by the recipient, end-to-end encryption methods such as S/MIME are used.
- On a website: SSL only encrypts the connection. It does not guarantee that the site is free of viruses or that it is not fraudulent; fake sites can obtain an SSL certificate too. To recognise fake sites and suspicious links, see the guide How to spot a phishing email.
: Enlarge
Website SSL and email SSL compared
| Website SSL | Email SSL | |
|---|---|---|
| What does it protect? | The data between the visitor's browser and the site (forms, passwords, cards) | The password and messages between your email program and the mail server |
| Who sets it up? | The site owner or the hosting company (a certificate is installed on the server) | The email provider supplies it on the server; you select SSL/TLS or STARTTLS in your program |
| What does the user see? | An https address and a padlock icon; otherwise a "Not secure" warning | The SSL/TLS option and the port (993, 995, 465 or 587) in the account settings |
| Risk if it is off | Forms and passwords can be read on the network; the browser warning drives visitors away | The password is sent as plain text; the account can be taken over, and many providers refuse the connection |
Types of SSL certificate for a website
- DV (domain validated): Only control of the domain name is verified. It is sufficient for most corporate sites and blogs. Free certificates such as Let's Encrypt are of this type; many hosting companies install them from the control panel.
- OV (organisation validated): In addition to the domain name, the existence of the organisation is verified.
- EV (extended validation): The most thorough form of organisation validation. Today's browsers may not show any visible difference between EV and DV.
Whichever type is chosen, the connection is encrypted to the same strength; the difference lies in the extent of the identity checks carried out by the certificate issuer.
Why does SSL matter on your website?
- Visitors' form, membership and payment details are protected; for e-commerce sites and sites with payments or forms, SSL is effectively mandatory.
- The browsers' "Not secure" warning drives visitors away from the site.
- Google has stated that it treats https as a positive signal in search ranking.
- Keep track of the certificate's expiry date or make sure it renews automatically; an expired certificate triggers a warning when the site is opened.
- SSL alone is not enough: to redirect all traffic to the HTTPS address and turn on browser protections, see Security headers and HTTPS, and for the rest of the site, see the Website security guide.
Frequently asked questions
Are SSL and TLS the same thing?
In practice they are used for the same purpose. SSL is the name of the old protocol; the secure version in use today is TLS. Expressions such as "SSL certificate" and "use SSL" persist out of habit.
My site shows a padlock icon; is the site secure?
The padlock icon only shows that the connection is encrypted and that the certificate was issued for that domain name. It does not guarantee that the content of the site is trustworthy or that it is not fraudulent.
If SSL is on in email, are my messages completely private?
No. SSL protects the connection between your device and your mail server. For a message to be encrypted end to end all the way to the recipient, separate methods such as S/MIME are needed.
Are my website's SSL and my email's SSL the same certificate?
If they are hosted on the same server, the same certificate may be used, but this depends on the provider. The server name you enter in your email program must match the name on the certificate; otherwise you will get a certificate warning.
BYK Yazılım Support Team
This guide is written and regularly reviewed by the BYK Yazılım support team. Last updated: 4 October 2026.
Related guides
- How to spot a phishing emailThe tell-tale signs of fake emails, how to check links and attachments, and what to do if you clicked.
- Security headers and HTTPSHSTS, CSP, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, with an .htaccess example.
- How to create a strong password. What is a password manager?Long passwords that are never reused, passphrases, and how to use a password manager.
- What is two-factor authentication and how do you turn it on?Add a second layer of security to your accounts: verification methods and the general route for Google and Microsoft accounts.
Let us review the security of your software together
BYK Yazılım supports the websites and software it develops with updates and security. Contact us with your questions.
Contact us Our corporate website service