A connection, in three parts
When you open an HTTPS address, your browser establishes an encrypted connection to the server answering for that website. It negotiates how to protect the connection and checks the server’s certificate.
| Part | What happens |
|---|---|
| Find | DNS helps translate a hostname into a network address. |
| Verify & connect | TLS establishes keys and lets the browser verify the server’s identity. |
| Exchange | HTTP requests and responses travel through the encrypted connection. |
What encryption protects
HTTPS protects the contents of HTTP requests and responses in transit. Paths, query strings, form data, and page contents travel inside the encrypted connection. A network observer should not be able to read or silently change those contents.
The website still receives the information you send it. If a content delivery network terminates TLS for the website, that provider can also access the HTTP exchange.
A secure connection does not tell you whether the website’s operator is trustworthy.
What can remain visible
Destination IP addresses, traffic volume, and timing can remain observable. Ordinary DNS requests may disclose the hostname. Without Encrypted ClientHello (ECH), the TLS handshake can also expose the name through Server Name Indication.
ECH can protect that part of the handshake when the client and server successfully use it. It does not erase other traffic patterns. The ECH viewer shows the public configuration advertised for this website.
Three useful habits
- Check the actual domain name before entering private information. A lookalike site can also have HTTPS.
- Investigate certificate warnings. Check the address and your device’s clock before proceeding.
- Keep the browser and operating system updated so that security fixes and protocol improvements reach your device.