How do I check if my website is secure?
Updated
Check for the padlock and https:// in the address bar, on your phone as well. Then run your address through SSL Labs' free Server Test to check the certificate. Keep your website software and plugins updated, and turn on two-step sign-in. Set up SPF, DKIM and DMARC too, so nobody can easily send email as you.
Check it yourself, with free tools
- Look at the address bar. Open your site on a phone and a computer. You should see a padlock and no "Not secure" warning. Chrome shows that warning when a page doesn't use a secure (https) connection.
- Type the plain version. Enter
http://yourbusiness.comwithout the "s". It should jump straight to the https version. - Test the certificate. Paste your address into the SSL Labs Server Test (
ssllabs.com/ssltest). It grades your certificate and connection from A to F. - Test the security settings. Mozilla's HTTP Observatory checks the protective settings your server sends with each page.
- Test your email records. A DMARC lookup, such as MXToolbox's, shows whether your domain is protected against fake emails in your name.
- Check your domain's renewal date. Ask your registrar, or look in your account. A lapsed domain takes your website and email offline.
Keeping it secure
- Update your software. WordPress's own guidance says to keep plugins updated, and to delete the ones you don't use. The US cyber agency, CISA, calls keeping systems patched one of the most cost-effective things you can do.
- Turn on two-step sign-in for your website admin, hosting, domain and email accounts. CISA says to start with email.
- Keep a backup you can restore, stored away from the website itself.
- Remove old logins. Delete accounts for past staff and old web designers.
- Get a free certificate. Let's Encrypt is a free certificate authority. Ask your host to switch it on and renew it automatically.
If something has already gone wrong, see something broke: your first 30 minutes.
Common questions
Does the padlock mean my website is safe?
Not on its own. It means the connection between the visitor and your site is encrypted. It says nothing about whether your software is up to date or your passwords are strong.
Do I have to pay for an SSL certificate?
Usually not. Let's Encrypt gives free certificates, and many hosts include them. Ask your host to switch one on.
Is Chrome changing how it treats sites without https?
Yes. Google has said Chrome 154, due in October 2026, will turn on "Always Use Secure Connections" by default. Visitors will then see a warning before a page without https opens.
What are SPF, DKIM and DMARC?
They're three records on your domain that prove your emails really come from you. Google requires every sender to Gmail to have SPF or DKIM. Anyone sending 5,000 or more emails a day to Gmail needs all three.
Sitecomb checks the outside of your website for these problems. It covers https on every page, your certificates and security settings. It also checks for outdated JavaScript libraries, your email records and your domain's expiry date. Security is one of six areas in a €9.99 report. It can't see inside your admin area, so updates and passwords stay with you.
Sources
- Google Chrome Help — Check if a site's connection is secure
- Google Security Blog — HTTPS by default
- Let's Encrypt — About
- Qualys SSL Labs — SSL Server Test
- MDN — HTTP Observatory
- WordPress — Hardening WordPress
- CISA — Cyber guidance for small businesses
- UK NCSC — Small Organisations Guide to Cyber Security
- Ireland NCSC — Cyber security for small business (PDF)
- Google Workspace Admin Help — Email sender guidelines