Browsers don't inherently trust every SSL certificate — trust flows through a defined chain rooted in certificate authorities.
What a Certificate Authority Does
A CA verifies a certificate applicant's identity (or just domain ownership, for basic certificates) and digitally signs the certificate, vouching for its legitimacy.
The Chain of Trust
Browsers ship with a built-in list of trusted root CAs. A certificate is trusted if it can be traced back through a valid chain to one of these roots — break that chain, and browsers show a security warning.
Let's Encrypt as a CA
Let's Encrypt is itself a recognized, trusted certificate authority, issuing free certificates through the same chain-of-trust system as paid providers.
Español
Deutsch