When your browser says 'Not Secure' or 'Your connection is not private,' what should you do? Learn what each warning means, when it's safe to proceed, and when to leave immediately.
You click a link and your browser flashes a warning. “Not Secure.” “Your connection is not private.” “Deceptive site ahead.” A red screen with a triangle icon.
Is the site dangerous? Should you leave? Or is it a false alarm?
Browser security warnings are designed to protect you, but they’re not all equal. Some mean “this site will steal your data.” Others mean “the site owner forgot to renew a certificate.” Knowing the difference keeps you safe without making you panic over nothing.
This guide explains every common browser warning, what it actually means, and what you should do.
In Chrome, Firefox, and Safari, the address bar shows “Not Secure” (or a triangle with an exclamation mark) next to the URL. The page still loads normally.
The site is loading over HTTP, not HTTPS. Data between your browser and the website travels unencrypted. Anyone on the same network (public Wi-Fi, ISP, employer) can see and modify the traffic.
Not necessarily. It means the connection isn’t encrypted — not that the site is malicious. Many legitimate but outdated sites still use HTTP. However, you should never enter passwords, credit card numbers, or personal information on a non-HTTPS page.
HTTPS means the connection is encrypted. It does NOT mean the site is trustworthy. As we explain in our guide on why SSL doesn’t mean safe, every phishing site now has HTTPS. The padlock proves encryption, not honesty.
A full-screen warning in Chrome with a red triangle. The page does not load. The message says “Attackers might be trying to steal information” followed by error codes like NET::ERR_CERT_COMMON_NAME_INVALID or NET::ERR_CERT_DATE_INVALID.
The site has an HTTPS certificate, but something is wrong with it:
ERR_CERT_DATE_INVALID: Probably not dangerous — just poorly maintained. Many small sites let certificates lapse. But a lapsed certificate means the connection can’t be verified, so proceed with caution.
ERR_CERT_COMMON_NAME_INVALID or ERR_CERT_REVOKED: Potentially dangerous. The mismatch could indicate a man-in-the-middle attack or a phishing site. Do not bypass this warning.
A bright red full-screen warning. Chrome shows “Deceptive site ahead.” Firefox shows “Warning: Potential Security Risk Ahead.” The URL is completely blocked — you have to click through multiple warnings to access the page.
Google’s Safe Browsing service (used by Chrome, Firefox, and Safari) has flagged this site as:
Yes. This is the most serious warning. Google has verified that the site is actively harmful. These warnings are rarely false positives.
Leave immediately. Do not click “Details” or “Proceed to site.” Do not enter any information. Close the tab.
If you believe the warning is a false positive (it happens to legitimate sites that have been compromised), check the site using a trust audit tool to see if other risk signals are present.
A red warning screen stating the site contains harmful programs or malware. Similar to the deceptive site warning but specifically focused on malicious software distribution.
The site hosts downloadable files or scripts that are detected as malware, adware, or unwanted software by Google’s scanners. The site may be:
Do not download anything from this site. If you were sent here by a link from someone you know, their account may be compromised. Leave and warn them.
When you download a file, Chrome shows “Dangerous file” or blocks the download entirely with a note that the file is “dangerous” or “malicious.”
Chrome’s built-in scanner (and Google Safe Browsing) identified the file as:
Do not open the file. Delete it immediately. If it’s a file you expected from a trusted source, scan it with antivirus software before opening. If the source is a website you’ve never verified, check the site’s reputation before re-downloading.
The address bar shows HTTPS (padlock), but Chrome shows a small warning icon or console message about “mixed content.” The padlock may be replaced with a “Not Secure” label.
The main page loads over HTTPS, but some resources on the page (images, scripts, stylesheets) load over HTTP. This creates a partial encryption gap — an attacker could intercept or modify those unencrypted resources.
Usually not dangerous to visitors — it’s a developer error. But it does mean the page isn’t fully secure. If a script loads over HTTP on an HTTPS page, an attacker could potentially inject malicious code through that script.
In Chrome, a new “Privacy” or “Tracking protection” icon (shield shape) appears in the address bar. Clicking it shows how many trackers were blocked.
This isn’t a security warning — it’s a privacy notification. Chrome blocked third-party cookies or tracking scripts on this page.
Nothing. This is informational. It actually means Chrome is protecting your privacy on this site.
| Warning | Meaning | Risk Level | Action |
|---|---|---|---|
| ”Not Secure” | No HTTPS encryption | Low (reading) / High (data entry) | Don’t enter sensitive info |
| ”Connection not private” | Certificate error | Medium to High | Check error code; don’t bypass on financial sites |
| ”Deceptive site ahead” | Phishing/social engineering | Critical | Leave immediately |
| ”Harmful programs” | Malware distribution | Critical | Leave immediately |
| ”Dangerous file” | Malicious download | High | Delete the file |
| Mixed content | Partial encryption | Low | Avoid entering data |
| Tracking protection | Privacy shields active | None | No action needed |
Regardless of the warning type, never proceed if:
Browser warnings catch known threats, but they can’t detect every scam. A site can have valid HTTPS, no malware, and no browser warnings — and still be a scam.
For a thorough check:
Browser warnings are your first line of defense, but they’re not your only one. Here’s the hierarchy:
The most dangerous mistake isn’t ignoring a warning — it’s assuming the absence of warnings means a site is safe. HTTPS is free and takes 10 minutes to set up. Every scam site has a padlock now. Use browser warnings as a first filter, not a final verdict.
Want a deeper check than your browser’s warning? Run a free trust audit on any URL — domain reputation, fraud detection, monetization transparency, and AI-powered risk assessment in under 10 seconds.
Check any website in 10 seconds
Paste a URL. Get a full trust audit — domain reputation, fraud signals, monetization analysis.
Run a free scan