Expired SSL certificate
Right now, your site greets every visitor with a security warning.
An expired SSL certificate doesn't degrade gracefully — browsers throw a full-screen 'Your connection is not private' wall, and most visitors obey it. The site behind the wall is fine. Nobody's getting far enough to know that.
Same-day diagnosis. Flat quote before any fix.
What’s actually happening
The SSL/TLS certificate is what makes the padlock — proof that your site is who it claims to be, and that traffic to it is encrypted. Certificates deliberately expire (most now every 90 days) so stale credentials can't float around the web forever; renewal is meant to be automatic, and this error is what it looks like when automation quietly stopped.
Expiry is binary. One minute past the deadline and Chrome, Safari, and Firefox all throw the interstitial, search crawlers note the failure, and every API or webhook that calls your site starts refusing the connection too — which is why an expired cert sometimes breaks payments and integrations before anyone even sees the browser warning.
The usual causes, ranked
After twenty-seven years of these calls, the odds are well mapped. Start at the top.
Auto-renewal silently failing
The dominant case for Let's Encrypt-style certs: a renewal cron that died, a DNS change that broke validation, or a server config the renewer can't write to. It worked for months of 90-day cycles — until it didn't.
The certificate was never set to auto-renew
Paid certificates bought annually expire annually, and the reminder email went to whoever built the site in 2021.
DNS or domain changes broke validation
Renewal proves domain control via DNS or an HTTP check. Moved DNS, added a proxy like Cloudflare, or changed hosts? The proof can fail while everything else works.
The wrong certificate is being served
Multi-domain servers sometimes serve a valid cert for the wrong hostname — technically live, practically identical to expired for the visitor.
What you can safely try first
Nothing below can make things worse — that’s the selection criterion. Anything riskier belongs in professional hands, on a backup.
- 1
Confirm what the browser actually says
Click the warning's details: 'expired on [date]' is renewal; 'wrong site name' is a serving problem; 'not trusted' is an install problem. Three different fixes, one screen apart.
- 2
Check your hosting panel's SSL section
Most hosts show certificate status and a renew/reissue button. If the button works, you're done in minutes — the better question is why automation didn't press it for you.
- 3
Note any recent DNS, CDN, or host changes
If the expiry followed a migration or a Cloudflare setup, the validation path is the suspect — and the renewal will keep failing until that's fixed, not just retried.
Stop and call when…
- Renewal 'succeeds' but the browser still shows the old certificate
- Payments, webhooks, or integrations started failing alongside the warning
- You've renewed manually twice — the fire drill needs an actual fix
From there it’s our job: same-day look, flat quote, and the $229 flat repair covers most cases of exactly this.
Single Error Fix — buy it now, skip the hunt.
One error, hunted down and fixed — 500s, white screens, redirect loops, broken pages.
Covers one specific error or broken behavior on one site. Diagnosis, the fix, and a plain-English note on what happened. If we can't fix it, you get a full refund.
Questions we hear a lot.
Is my site down?
Not technically — it's fully running behind the warning. Practically, yes: the interstitial turns away most visitors, and automated systems refuse the connection outright. Treat it with down-site urgency; it costs like downtime.
Is it dangerous to click through the warning myself?
To your own known site, briefly, to verify it's the expiry and nothing else — that's reasonable. The warning exists because an invalid certificate could mean interception; asking customers to click through is asking them to learn a terrible habit on your brand.
Why do certificates expire every 90 days now?
Short lifetimes limit the damage of stolen or misissued certificates and force the ecosystem toward automation. The trade: renewal must be automatic and monitored, because 90-day cycles mean four chances a year for silent failure.
What does the fix include?
Renewal or reissue, correct installation, and — the part that matters — repairing the automation and validation path so the fire drill retires. $229 flat, and it includes checking that mail, APIs, and subdomains are covered too.
Related symptoms & help
Errors travel in packs. If this one visited, check its friends.
Drop the warning wall. Retire the fire drill.
Send the symptom, get a same-day look and a flat quote from the developer who's fixed this exact thing more times than either of us can count.