You get an SMS that looks like it is from your bank. It says your account needs urgent verification, with a link attached.
You tap it, the page loads, and there it is, the little padlock sitting next to the address bar. It looks secure, so you type in your PIN.
That padlock did exactly what it was designed to do. It just did not do what you assumed it would.
HTTPS never promised the website was honest.
It only promised that nobody else could read the data traveling between your phone and whatever server sits on the other end, honest or not.
This confusion costs people real money every year, and it is worth understanding exactly what that green padlock checks, what it skips entirely, and how scammers have learned to use it against the very habit banks and cybersecurity trainers spent years building.
What the Padlock Actually Verifies
An SSL certificate does two specific jobs.
First, it encrypts the connection between your browser and the website’s server, so a stranger on the same WiFi network cannot read your password as it travels.
Second, it confirms that you are actually talking to the Domain shown in your address bar, rather than some other server pretending to be it.
That second point is where the confusion begins. The certificate confirms the Domain, not the company behind it.
If a scammer registers a domain like safar1com-verify.com and gets a certificate, the padlock will appear, and it will be telling the truth.
You really are talking to safar1com-verify.com. The certificate has no way of knowing that the Domain has nothing to do with the real Safaricom.
The Numbers Tell the Real Story
Security researchers have tracked this shift for years, and the trend only moves in one direction.
According to phishing data cited by Kaspersky, roughly a quarter of all phishing attacks now run on HTTPS sites, up from under one percent just two years earlier, when that figure was first tracked.
Keyfactor’s research goes further, finding that in a single quarter, over 90 percent of phishing sites analyzed were running on Domain Validated certificates, the cheapest and least strict validation level available.
Only a small fraction used Organization Validated certificates, and virtually none of the fraudulent sites managed to obtain Extended Validation certificates, the strictest tier that verifies a real, registered business.
More recent industry monitoring puts the share of phishing sites using HTTPS above 80 percent.
Put plainly, the padlock has gone from being a rare marker of trustworthy sites to something nearly every scam page displays as a matter of routine.
Why Free Certificates Changed the Game
None of this would be possible at scale if SSL certificates still cost money and required identity checks, the way they did in the early 2000s.
Free, automated certificate services changed that completely.
A domain owner can now request and receive a fully valid, browser-trusted certificate in seconds, with no proof of who they are or what they plan to use the Domain for.
This was never a flaw in how those services work. Domain-validated certificates were always meant to confirm domain ownership, nothing more.
The problem is that most people were taught to treat the padlock as a general safety signal, back when getting one took real effort and cost real money.
That advice made sense twenty years ago.
It stopped making sense the moment free, instant certificates became available to anyone with a domain name and five minutes to spare.
How a Convincing Fake Gets Built
Scammers building a lookalike site follow a predictable pattern, and recognizing it is often more useful than any single technical check.
- Registering a near-identical domain. This usually means swapping a letter, adding a hyphen, or changing the extension. A fake M-Pesa page might use mpesa-secure.com instead of the real safaricom.co.ke, banking on the fact that most people glance at a URL rather than reading it character by character.
- Obtaining a free, instant certificate. The moment the Domain is registered, a Domain Validated certificate can be issued automatically, since the process only checks that whoever requested it controls the Domain, which they do.
- Cloning the real site’s design. Phishing kits sold on underground forums often come with the target’s logo, color scheme, and page layout already built in, sometimes with the certificate request automated as part of the same kit.
- Creating urgency. Fake account suspension notices, missed delivery fees, or tax refund claims push people to act quickly, before they stop to check the address bar carefully.
Kenyan users see localized versions of this pattern constantly.
Fake M-Pesa balance or PIN reset pages, fraudulent KRA iTax refund notices, and cloned bank login pages sent through SMS all follow the same four steps above, and nearly all of them now carry a valid padlock.
An example:
Imagine an SMS arrives claiming your M-Pesa account has been temporarily limited, with a link to “verify” it immediately. The link opens a page at mpesa-account-verify.net.
It has the Safaricom green branding, the M-Pesa logo, and a padlock in the address bar.
Every visual signal matches what a cautious user was taught to look for. The page is encrypted. It has a certificate.
It even loads instantly, which people mistake for a sign of a well-run, legitimate service.
None of that changes the fact that Safaricom does not own mpesa-account-verify.net, and the certificate authority that issued its SSL certificate never checked that detail.
This is because Domain Validated issuance was never built to check it.
Domain Validation, Organization Validation, and Extended Validation
Not every SSL certificate checks the same things, and understanding the difference explains why some certificates are far harder for scammers to obtain.
- Domain Validated (DV): confirms only that whoever requested the certificate controls the Domain. This is the fastest, cheapest option, often free, and it is what nearly every phishing site uses because there is nothing to stop a scammer from proving they own a domain they just registered themselves.
- Organization Validated (OV): requires the certificate authority to verify that a real, registered business exists behind the Domain, checking official business records before issuing anything. This takes longer and costs more, which is exactly why phishing sites almost never bother.
- Extended Validation (EV): requires the most rigorous check, confirming the legal business name, registration, and physical operating address before issuance. This is the tier attackers essentially never reach, since it demands the kind of paperwork trail a fraudulent operation cannot produce.
None of these certificate types changes what encryption does. All three secure the connection equally well.
What changes is how much the certificate authority actually verifies who is on the other end.
And that difference is exactly what scammers exploit by sticking to the cheapest, least verified option available.
Red Flags That Matter More Than the Padlock
Since the padlock alone cannot tell you whether a site is legitimate, a handful of other checks matter far more.
- Read the domain character by character rather than glancing at it, watching for swapped letters, added hyphens, or an unfamiliar extension in place of .co.ke or .com.
- Treat urgency as a warning sign rather than a reason to act fast. Real banks and M-Pesa rarely demand an immediate PIN entry through a link sent by SMS.
- Never follow a link from an unexpected message to reach a banking or payment page. Type the address directly or use the official app instead.
- Check how long the Domain has been registered, where possible. Most phishing domains are only days or weeks old before they get shut down or blocked.
- Look at the certificate type itself. Click the padlock and view certificate details. A DV certificate on a page asking for banking credentials deserves extra suspicion, while a legitimate bank almost always uses OV or EV certificates on its actual login pages.
What to Do Before You Enter Sensitive Information
A few seconds of caution before typing a password or PIN stops nearly every one of these scams cold.
Close the message or email and open your banking app directly, or type the known address into your browser from memory rather than tapping a link.
If a site is asking for your M-Pesa PIN, a one-time password, or your full card number, pause and verify through a second channel, such as calling your bank’s official number, before continuing.
If you run a business yourself, this cuts both ways. Customers are learning to distrust the plain padlock.
It means a Domain Validated certificate alone may no longer be enough to reassure them on pages that collect payment details.
Moving your checkout or login pages to an Organization Validated certificate gives visitors a verified business name to check, something a DV certificate cannot offer.
What This Means If You Run a Kenyan Business
Every business collecting M-Pesa details, card payments, or account logins is competing for the same trust that scammers are actively working to fake.
A visitor who has been burned once, or who has read a warning like this one, will start checking more than the padlock before they type anything sensitive.
An Organization Validated certificate lets a genuine business show its verified legal name directly in the certificate details, something no fraudulent lookalike site can replicate without first registering a real company and passing a manual review.
For a SACCO, a school collecting fee payments, or an online shop taking M-Pesa or card details, that verified identity is a small technical detail that quietly answers the exact question a cautious customer is now asking.
Truehost issues Organization Validated SSL certificates in Kenya alongside standard Domain Validated options, with our support team able to advise on which level fits a site that handles logins or payments.
Getting this right once, at setup, is far less work than rebuilding customer trust after a scam using your brand name gets reported.
Frequently Asked Questions
- If a site has HTTPS, does that mean my data is at least encrypted?
Yes. Encryption is the one thing every valid SSL certificate genuinely guarantees, regardless of validation level. The data traveling between your browser and that server cannot be read by someone else on the network. It says nothing, however, about whether the server on the other end is trustworthy.
- Can a certificate authority refuse to issue a certificate to a known scam domain?
Rarely, and only after the fact. Domain Validated issuance is automated and only checks domain control, so a newly registered lookalike domain will typically pass without any manual review. Certificates get revoked after a site is reported and confirmed malicious, but that often happens after damage is already done.
- Does the type of certificate affect how fast a website loads?
No. Encryption speed is essentially identical across Domain Validated, Organization Validated, and Extended Validation certificates. The difference between them is entirely about identity verification, not performance.
- Should my business avoid a Domain Validated certificate altogether?
Not necessarily. A DV certificate is fine for a blog or an informational site with no login or payment forms. Any page that collects passwords, PINs, or payment details is worth securing with at least an Organization Validated certificate, since it gives visitors a verified business identity to check.
- How can I tell what validation level a certificate uses?
Click the padlock icon in your browser, then view the certificate details. A DV certificate typically shows only the domain name. An OV or EV certificate will also display the verified organization’s legal name and location.
- Why do so many legitimate small businesses still use Domain Validated certificates?
Cost and speed. DV certificates are often free and are issued instantly, which makes them the practical default for informational sites, blogs, and pages without login or payment forms. The recommendation to upgrade applies specifically to pages handling sensitive data, not to every page a business runs.
- Does clearing my browser cache or using incognito mode protect me from a fake HTTPS site?
No. Neither of those affects certificate validation or domain verification in any way. They only control what your browser remembers locally, which has nothing to do with whether the Domain you are visiting is genuine.
The Bottom Line
HTTPS was never designed to answer the question people use it to answer.
It confirms encryption and domain ownership, not honesty or identity, and scammers have had years to build entire operations around exploiting that gap.
The padlock still matters, since its absence is a genuine red flag, but its presence alone tells you far less than most people assume.
Read the address bar carefully, treat urgency as suspicious, and reserve your banking details for pages you reach on your own terms.
That habit protects you long after any single certificate check would have failed.
Domain SearchInstantly check and register your preferred domain name
Web Hosting
cPanel HostingHosting powered by cPanel (Most user friendly)
KE Domains
Reseller HostingStart your own hosting business without tech hustles
Windows HostingOptimized for Windows-based applications and sites.
Free Domain
Affiliate ProgramEarn commissions by referring customers to our platforms
Free HostingTest our SSD Hosting for free, for life (1GB storage)
Domain TransferMove your domain to us with zero downtime and full control
All DomainsBrowse and register domain extensions from around the world
.Com Domain
WhoisLook up domain ownership, expiry dates, and registrar information
VPS Hosting
Managed VPSNon techy? Opt for fully managed VPS server
Dedicated ServersEnjoy unmatched power and control with your own physical server.
SupportOur support guides cover everything you need to know about our services


