SSL Certificate Expired
Higher-risk issue — be cautious and consider professional help sooner.
Your site's SSL certificate ran out, so every visitor now gets a full-page browser warning instead of your website — usually because an automatic renewal quietly failed.
Common signs of this issue
- Visitors see a full-page warning such as "Your connection is not private" with the code NET::ERR_CERT_DATE_INVALID.
- An online SSL checker or the browser's certificate details show an expiry date that has passed.
- The site was working normally until a specific day, then broke for everyone at once with no changes on your end.
- Traffic, orders, and inquiries drop sharply from that day, and customers start reporting a security warning.
- You find an unread renewal-failure email from your host, your certificate provider, or Let's Encrypt — sometimes weeks old.
- The site recently moved to a new server or changed DNS, and this is the first certificate renewal since the move.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Confirm the diagnosis with a free online SSL checker (search "SSL checker" — paste in your domain, no login needed). It shows the exact expiry date, who issued the certificate, and which names it covers. If the date has passed, you have your answer.
- Check both forms of your address — www and the bare domain. Sometimes only one certificate expired, or the renewal replaced one but not the other.
- Log in to your hosting control panel and find the SSL/TLS or Security section. Many hosts show certificate status there, often with a run-renewal or reissue button that fixes it on the spot.
- Search your email — including spam — for messages from your host, your certificate provider, or Let's Encrypt about a failed renewal. The notice usually names the reason: an unreachable domain, a DNS problem, or a payment issue.
- Ask what changed since the last successful renewal: a move to a new server, a DNS change, turning on Cloudflare, or a domain transfer. Renewals that ran happily for years commonly break at the first attempt after a change like that.
- If the certificate was paid for, check the account with the certificate seller — an expired credit card or a missed renewal invoice quietly ends a paid certificate on its anniversary.
- If none of that resolves it, open a ticket with your host saying "my SSL certificate expired and auto-renewal appears to have failed" — on managed hosting this is routine, and they can usually reissue within minutes to hours.
What this usually means
SSL certificates have fixed lifetimes on purpose — free ones from Let's Encrypt last about 90 days, paid ones typically a year — and are meant to renew automatically before they run out. An expiry that reaches visitors means the renewal machinery failed and nobody noticed the warnings. The certificate didn't break; the process around it did.
The silent failures follow patterns. A site moves to a new server, but the scheduled renewal task stayed behind on the old one — or never got set up on the new one. DNS changes and the renewal check can no longer reach the domain to prove you own it. A DNS record called CAA quietly forbids issuance. A paid certificate's card on file expires. Or the site sits behind Cloudflare, which shows visitors its own valid certificate — masking the expired one on the origin server until a setting makes it matter.
Who fixes it depends on your setup. On managed hosting, site builders, and most cPanel hosts with free AutoSSL, the certificate is the platform's responsibility — your job is to open the ticket and confirm it is resolved. If you run your own server or a developer set up Let's Encrypt manually, the renewal task is yours (or theirs) to repair, not just rerun once. Either way the goal is the same: fix the renewal, not merely this expiry, so it never reaches visitors again.
What not to do
- Don't tell visitors to click past the warning — browsers make that deliberately hard, it looks unprofessional, and it teaches customers a dangerous habit.
- Don't rush to buy a certificate from a third-party seller before checking your host — most hosts now include free certificates and can reissue one immediately at no cost.
- Don't just renew and move on. If the automatic renewal failed once and the cause isn't fixed, you will be back here in about 90 days.
- Don't assume the site was hacked. An expired certificate is a lapsed formality, not an intrusion — but visitors can't tell the difference, which is why speed matters.
- Don't make unrelated changes mid-fix — switching Cloudflare modes, forcing https redirects, or moving DNS while the certificate is being reissued muddies the water and can create new errors.
- Don't ignore renewal-warning emails in the future — they typically arrive weeks before expiry, plenty of time to fix a renewal calmly instead of during an outage.
When to get help
If your host's control panel has a renew button, or the host reissues the certificate from a support ticket, you may not need outside help at all — that is the normal path on managed hosting. A professional pays for themselves when the renewal keeps failing and nobody can say why: the usual culprits are a renewal task still running on a server you left months ago, a DNS or CAA record blocking issuance, or a Cloudflare configuration hiding the real state of the origin server. Someone who handles certificates routinely can trace which it is quickly, repair the renewal so it runs unattended again, and add monitoring so a future failure emails you weeks ahead instead of surprising your customers. An expired certificate turns visitors away as effectively as the site being down — the sensible spend is whatever gets it verifiably fixed today, and makes it a problem you never buy twice.
Could your hosting be the problem?
If your host is slow, unreliable, or hard to deal with, moving to a better one can clear up issues like this for good. One we genuinely recommend is Instant Access Internet Services — a smaller, compassionate company with 30 years in the business, known for being one of the fastest, with great management and low pricing. (Just a recommendation — no affiliate link, no kickback.)
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What happens when an SSL certificate expires?
Browsers stop trusting the connection and show every visitor a full-page warning instead of your site. The site itself is untouched, but in practice almost nobody clicks past the warning, so traffic and sales stop until the certificate is renewed.
Why did my SSL certificate expire if renewal is automatic?
Because the automatic renewal quietly failed. Common causes: the site moved servers and the renewal task stayed on the old one, DNS changed so the renewal check couldn't verify the domain, a blocking DNS record, or an expired payment method on a paid certificate. Fix the cause, not just this expiry.
Whose job is it to renew my SSL certificate?
On managed hosting and site builders, the host or platform issues and renews certificates — open a ticket and they fix it. If you or a developer set up the certificate manually on your own server, the renewal setup is on your side. When in doubt, ask your host first; the answer is usually them.
How much does it cost to renew an SSL certificate?
Usually nothing. Most hosts include free certificates from Let's Encrypt or similar and renew them automatically. Paid certificates still exist for special cases, but a typical small business site doesn't need one — check what your host includes before buying anything.
How do I stop my SSL certificate expiring again?
Fix the renewal mechanism rather than renewing by hand, confirm the next automatic renewal actually happens, and set up free expiry monitoring — several services will email you weeks before a certificate runs out. After any server move or DNS change, check that renewals still work.