ERR_SSL_PROTOCOL_ERROR: This Site Can't Provide a Secure Connection
Chrome or Edge shows "This site can't provide a secure connection" with the code ERR_SSL_PROTOCOL_ERROR — the browser tried to open a secure connection to your site and the server's answer made no sense to it.
Common signs of this issue
- Chrome or Edge says "This site can't provide a secure connection" and "yoursite.com sent an invalid response" with the code ERR_SSL_PROTOCOL_ERROR.
- Firefox shows "Secure Connection Failed", sometimes with the code SSL_ERROR_RX_RECORD_TOO_LONG, for the same address.
- There is no "Advanced" or "Proceed anyway" link like there is on a certificate warning — the page simply will not open.
- It started right after moving to a new host, switching on HTTPS, adding Cloudflare, or changing DNS.
- The http:// version of the site may still load, but anything starting with https:// fails.
- It fails on one computer or one office network but works fine on your phone over mobile data.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Test from a second device on a different network — your phone with Wi-Fi turned off is ideal. If the site opens there, the problem is on the first computer or network (antivirus, firewall, clock). If it fails everywhere, the problem is on the server side.
- On the computer that fails, check the date, time, and time zone. A clock that is days or years off breaks secure connections in confusing ways. Set it to update automatically and try again.
- Try the site in a private or incognito window and in a second browser. If only one browser fails, a browser extension or cached setting is the likely cause, not your website.
- If you run antivirus or internet security software, look for a setting named something like HTTPS scanning, Web Shield, or encrypted connection scanning. Pause it briefly and reload. Security tools that inspect encrypted traffic are a well-known cause of this exact error. Turn it back on afterwards.
- Run your domain through a free outside checker such as SSL Labs' SSL Server Test (ssllabs.com/ssltest). If it cannot connect on port 443, reports no certificate, or says the server only speaks old TLS versions, you have confirmed a server-side problem and have something concrete to send your host.
- Think about what changed. If you recently moved hosts or changed DNS, the domain may now point at a server that has no certificate installed for it yet. In your new host's control panel, look for an SSL/TLS or "Let's Encrypt" / "AutoSSL" section and check whether your domain is listed as covered.
- If the site uses Cloudflare, log in and open SSL/TLS, then Overview. Note which mode is selected (Off, Flexible, Full, or Full (strict)) and check the Edge Certificates page to confirm a certificate is active for your domain. A newly added domain can take a little while before Cloudflare's certificate is ready.
- Try both
https://yourdomain.comandhttps://www.yourdomain.com. If one works and the other fails, the certificate or server setup only covers one of them — a very common leftover from a migration. - Write down the exact error code, which browsers and networks fail, and when it started. That short note turns a vague "my SSL is broken" ticket into one your host can solve quickly.
What this usually means
ERR_SSL_PROTOCOL_ERROR is different from the more familiar "Your connection is not private" warning. That warning means the browser got a certificate and did not trust it. This error means the browser never got a sensible secure conversation started at all. The most common reason is that the server answering on the secure port (443) is not actually set up for HTTPS — for example, a freshly migrated site where no certificate has been issued yet, or a server that is answering secure requests with plain, unencrypted web pages. That last case is exactly what Firefox's SSL_ERROR_RX_RECORD_TOO_LONG code describes.
The second big group is a mismatch in how the two sides want to talk. Modern browsers no longer accept the old TLS 1.0 and 1.1 protocols, so an outdated server, an old load balancer, or a very old control panel setup can fail the handshake even with a valid certificate. A Cloudflare setting that does not match what your hosting server can do, or a domain that has only just been added to Cloudflare, can produce the same symptom. If the certificate exists but covers the wrong name, you will more often see a name mismatch warning instead; if Cloudflare cannot talk securely to your host, you will usually see a Cloudflare 525 or 526 error.
The third group is on the visitor's side: antivirus or firewall products that intercept secure traffic, corporate filtering, a badly wrong system clock, or a browser extension. The quick way to separate the two is the phone-on-mobile-data test. If the site fails for everyone, everywhere, it is a server or DNS problem and your visitors are seeing it too. If it fails only on one machine or network, your website is probably fine and the fix is local.
What not to do
- Don't install a random "SSL fixer" plugin as a first step. If the server itself is not serving HTTPS correctly, a plugin inside the site cannot fix it and may add redirect problems on top.
- Don't turn off HTTPS or tell visitors to use the http:// address. Browsers label that as Not Secure, and it hides the problem rather than fixing it.
- Don't leave antivirus HTTPS scanning switched off permanently after testing. Pause it to diagnose, then turn it back on or add an exception.
- Don't switch Cloudflare's SSL mode back and forth repeatedly hoping one sticks. Each change can take effect across different visitors at different times and makes the cause harder to pin down.
- Don't buy a new paid certificate before confirming one is actually missing. Most hosts provide free certificates, and the problem is often that the free one simply was not issued yet.
- Don't change DNS again mid-diagnosis. If you just moved hosts, give the certificate process a chance to finish before pointing the domain anywhere else.
When to get help
If the error shows up for everyone, on every network, your site is effectively offline for anyone typing https:// — which today is nearly everybody, including Google. That is when to stop experimenting. Someone who works with servers can check in minutes whether a certificate is installed, which TLS versions the server offers, whether port 443 is answering with the right site, and whether Cloudflare and the host agree on how to connect. The fix is usually a single correct setting or a reissued certificate; the risk of guessing is stacking a redirect loop or a mixed-content problem on top of the original fault.
Glenn, who runs WebsiteSelfHelp, sorts out SSL and HTTPS problems like this for small businesses, including the messy ones left behind by a host move. Ask for a direct review, tell him the error code and what changed recently, and you will get a plain answer on what is wrong and what it takes to fix — you do not need to hand over any passwords to start.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does ERR_SSL_PROTOCOL_ERROR mean?
It means your browser tried to set up a secure HTTPS connection with the website and the server's reply did not follow the rules of that process. The connection is dropped before any page is shown, which is why there is no option to click through.
Is ERR_SSL_PROTOCOL_ERROR a problem with my computer or the website?
It can be either. If the site also fails on your phone over mobile data, the problem is almost certainly on the server. If it only fails on one computer or one network, look at antivirus HTTPS scanning, the system clock, browser extensions, or a company firewall.
Why did this start right after I moved my website to a new host?
Your domain now points at the new server, but that server may not have issued a certificate for your domain yet, or the free certificate process failed because DNS was still settling. Check the new host's SSL section and ask them to issue or reissue the certificate.
Can Cloudflare cause ERR_SSL_PROTOCOL_ERROR?
Yes, mainly when a domain has just been added and its certificate is not ready, or when proxying and SSL settings do not match how your hosting server is configured. When Cloudflare itself cannot reach your host securely, you will more often see a Cloudflare 525 or 526 error page.
Will ERR_SSL_PROTOCOL_ERROR hurt my Google rankings?
If it affects everyone, yes. Google crawls the secure version of your site, and a site that cannot be opened securely looks down to Google just as it does to visitors. A short outage fixed within a day or two rarely causes lasting harm.
Does clearing my browser cache fix ERR_SSL_PROTOCOL_ERROR?
Occasionally, when the browser has cached an old secure-connection state for the site. It is worth one try, but if the site fails on other devices too, clearing your cache will not change anything for your visitors.
How much does it cost to fix an SSL protocol error?
Often nothing but time. Most hosts include free certificates, and the fix is usually issuing one or correcting a setting. You would only pay for someone's time to diagnose it, or for a hosting upgrade if the server is too old to support modern TLS.