Security certificate error
Your security certificate is broken. Most browsers now show visitors a full-page red warning before they can reach you.
How to see it yourself, in a minute
- Open your site in a private window in Chrome.
- A full-page red or grey warning saying your connection is not private, NET::ERR_CERT_DATE_INVALID or a name mismatch, is this fault.
- Click the padlock, then the certificate details: check the expiry date and that the name on it matches your domain.
Or paste your address into the free audit, which checks this and seventeen other faults in ten seconds.
Why it matters
An expired or mismatched certificate produces a full-screen browser warning that most people will not click through. To a visitor it looks like the business has been hacked or has closed.
This is the worst fault on the list because it stops everyone. Almost nobody clicks through a browser's full-page security warning, so for as long as it lasts the site is effectively down, and to a visitor it looks like the business has been hacked or has closed. Expired certificates are also a common reason email from the same domain starts going to spam.
How we fix it
We replace the certificate, set it to renew itself, and add a check that emails us three weeks before it could ever lapse again.
- Replace the certificate today, with the exact names it needs to cover (with and without www).
- Find out why it lapsed: nine times in ten the automatic renewal broke silently months ago.
- Set renewal to run itself and add a check that emails us at 21 days to expiry.
- Retest from outside the network on a phone, because the office often has the site cached.
How long: Same day.
Questions people ask about this
- It only just expired. Does it matter?
- Yes, from the first minute. Browsers block on the exact date. Some visitors will have seen the warning before you did, and they do not come back to check.
- Why did the renewal fail?
- Common causes: a hosting change, a firewall or a country block stopping the validation request, or software on the server that quietly broke. We find the cause rather than just renewing, or it happens again in 90 days.
- Can this be prevented?
- Entirely. Automatic renewal plus an expiry monitor means it cannot happen without two people being emailed first.
People usually find this page by searching
- “your connection is not private my website”
- “ssl certificate expired website”
- “net::err_cert_date_invalid fix”
Has your site got it?
Paste your address. This and seventeen other faults, checked in seconds.
Free, on screen in about ten seconds, no call. We fetch your homepage once, the way a visitor's browser does, and nothing else.
Or fix the lot at once
If the audit finds five or more, a rebuild is usually cheaper than five fixes. Prices are on the page.