What does this mean?
The root domain and www are distinct DNS names, even when they should show the same website. The root can work while www has no record, points to an old host, lacks certificate coverage or is not configured on the hosting account.
What should I check first?
Test both exact addresses over HTTPS and record whether failure is a DNS error, certificate warning or HTTP response. Do not change all domain settings to fix one hostname. A useful diagnosis distinguishes name resolution from TLS and from the application’s response.
How can I diagnose the cause?
Query A, AAAA and CNAME for www and compare with the host’s instructions. If DNS is correct, verify that www is added as a hostname or alias in the hosting panel. Inspect the public certificate to confirm it covers www; a root-only certificate does not necessarily cover that separate name.
How do I fix it safely?
Add the documented www record, configure the host alias and issue a certificate covering it. Choose whether www or the root is canonical, then create a path-preserving permanent redirect for the other. The redirect requires a working certificate on its HTTPS source before the browser can receive it.
Verify the fix and know when to contact your provider
Save DNS and redirect settings first. Test both schemes and both hostnames on a deep page, including its query string. Ask the host for help if resolution is correct but www serves the wrong site or certificate. Provide the exact hostname and observed failure stage, avoiding account credentials.
Work through these checks in order
- Query www with A, AAAA and CNAME as needed, then compare the result with the host’s required www setup. Do not remove the root domain’s working address during this test.
- If www resolves correctly, inspect its certificate and the hosting account’s configured domain aliases. The public address must be recognized by both the HTTPS service and the application.
- Test an existing deep page on www after correction. Its redirect should preserve the path and query string and finish at your chosen canonical hostname without an HTTPS warning.
Which tool can help?
DNS tools show one resolver’s public answers. Record explainers do not authenticate a message, and calculators do not monitor a server. Use the evidence alongside your provider’s logs.