What does this mean?
An HTTPS warning means the browser could not establish the expected authenticated connection. An expired certificate, wrong hostname, incomplete chain or incorrect device clock may be responsible. The warning should be investigated before asking visitors to enter passwords or payment details.
What should I check first?
Write down the browser’s exact error code and hostname. Check your device clock, then try another current browser or device. Open the browser’s certificate details to compare the covered names, expiry and issuer with the address you requested. A certificate for the root domain does not automatically prove www is covered.
How can I diagnose the cause?
Check both hostnames and any CDN or reverse proxy involved. A visitor can receive the CDN certificate while the CDN encounters a separate problem connecting to the origin. Inspect renewal status in the host’s certificate panel and confirm DNS points to the service holding the intended certificate.
How do I fix it safely?
Use the hosting provider’s renewal or installation procedure for the identified certificate. Install the required intermediate chain through the supported control panel. If issuance fails, review validation files or DNS records and any CAA restriction with the certificate provider. Do not disable HTTPS verification or redirect users to insecure login pages.
Verify the fix and know when to contact your provider
Keep copies of configuration before making changes, and never paste a private key into a checker. Retest the exact affected hostname after renewal and inspect its new dates. Contact the host when automated renewal repeatedly fails, the wrong certificate is served or the chain remains untrusted; provide the public certificate details and error code.
Work through these checks in order
- Open the browser’s certificate details and record the subject names, expiry date and exact trust error. Confirm that your device clock is correct before changing a certificate on a working server.
- Test the root and www names separately. Then check which service terminates HTTPS: a CDN’s public certificate and the origin server’s certificate can need separate repairs.
- After renewal, inspect the newly served certificate in a fresh connection. If the browser still shows the old one, ask the host or CDN which endpoint serves it rather than uploading the private key to a public tool.
Which tool can help?
SSL certificate checker (backend required) · Redirect checker (backend required) · HTTP status checker (backend required) · DNS lookup
DNS tools show one resolver’s public answers. Record explainers do not authenticate a message, and calculators do not monitor a server. Use the evidence alongside your provider’s logs.