The security certificate on your website has expired

The security certificate on your website has expired

A customer rings to say your website is showing a red warning, or you open it yourself and get a full-page message saying "Your connection is not private", "Not secure", or "This site's security certificate is not trusted". Usually this means the site's security certificate has expired.

The good news: your website has not been hacked, your files are intact and nothing has been lost. The bad news: to a visitor it looks alarming, and most will leave rather than click through the warning. So while it is a small technical problem, it is a real commercial one and worth fixing the same day.

What a certificate actually is

A certificate is a small file on your web server that does two jobs: it scrambles the connection between a visitor's browser and your site so nobody in between can read it, and it vouches that your site is really your site. It is what produces the padlock in the address bar and the https at the front of the address.

Certificates are issued for a fixed period and then expire. That is deliberate — it forces regular re-checking. Modern certificates are usually short-lived and renew automatically. When you see this error, either the automatic renewal has stopped working or the certificate was one that somebody had to renew by hand and the reminder went astray.

Try this first

  1. Check the site on your phone with wi-fi turned off. If it looks fine on mobile data but wrong in the office, the problem may be local to your network rather than the certificate itself.
  2. Check the date and time on your own computer. This one catches people. If your computer's clock is wrong by days or years, every secure site will show a certificate warning, because the browser thinks the certificate is not valid yet or has already lapsed. Right-click the clock, choose the date and time settings, and make sure it is set automatically.
  3. Try a different browser or a private window, which rules out a saved copy of an old certificate.
  4. Read the warning properly and note the wording. "Certificate expired" is different to "certificate name mismatch" (the certificate is for a different address, often www versus non-www) and different again to "issuer not trusted". Each points somewhere different.
  5. Check both addresses — with www and without. If only one is broken, that narrows it considerably.
  6. Look in the inbox that receives your domain and hosting notices, including junk. Renewal warnings usually go out well in advance, and finding that email tells us exactly which provider to deal with.

Please do not click through the warning and carry on using the site for anything involving logins or payment details, and do not ask customers to. The warning exists for a reason, even when the cause is innocent.

If that didn't fix it

This one is not really a do-it-yourself fix beyond the checks above — renewing and installing a certificate happens on the web server. Log a ticket and include:

  • The exact address showing the warning, with and without www.
  • The exact wording of the warning, or a screenshot.
  • Who hosts the site, if you know, and who manages the domain.
  • Whether anything changed recently — a new hosting plan, a site rebuild, a move to a new provider.

Once we know where the certificate lives, most cases are resolved quickly. Be aware that after a fix, browsers can hold on to the old certificate for a short time, so your own computer may keep showing the warning slightly longer than everyone else's.

How to stop it happening again

Expired certificates are almost entirely preventable, and the causes are boringly consistent:

  • Renewal notices go to an address nobody reads. An old staff member's mailbox, a personal address from when the site was first built, or a web designer no longer involved. Make sure every domain, hosting and certificate notice goes to a monitored business address.
  • Automatic renewal quietly stopped. Automatic renewal needs the site reachable and configured correctly, and a site rebuild or a move can break it without anyone noticing until the day it lapses.
  • Nobody is watching. Monitoring can check the certificate daily and warn well before expiry, which turns a public outage into a routine task.
  • Nobody knows who is responsible. Where the site was built by one party, hosted by another and the domain sits with a third, certificates fall between the gaps. Write down who owns each piece.

If you would like us to monitor your certificate and domain expiry dates so these never surprise you again, ask and we will set it up.

Still stuck?

Log a ticket at portal.yougrowit.com.au or email support@yougrowit.com.au. If it is stopping you working right now, call 03 9028 4358.

Support hours are Monday to Friday, 8:30am to 5:30pm Melbourne time, excluding Victorian public holidays.

    • Related Articles

    • Your website is offline: how to tell what is wrong

      You type in your web address and nothing loads, or you get an error page. Before anyone panics, the first job is to find out whether the site is genuinely down for everybody or whether it is only down for you. Those are completely different problems ...
    • Changing website or email provider without losing your email

      Moving your website or your email to a new provider is routine work and usually goes without incident. When it does go wrong, it almost always goes wrong the same way, and it is worth knowing what that way is before you sign anything. The mistake ...
    • Domain names: renewals, and why it matters who controls yours

      Your domain name — the yourbusiness.com.au part of your website and every staff email address — is one of the most valuable things your business owns, and one of the least understood. It is worth ten minutes to get right, because the failure modes ...
    • SPF, DKIM and DMARC in plain English

      If your emails are landing in customers' junk folders, or bouncing back with a message about authentication, someone has probably mentioned SPF, DKIM and DMARC. Here is what they actually are, without the jargon. All three are small settings ...