SSL Certificate Name Mismatch (ERR_CERT_COMMON_NAME_INVALID)
Browsers warn that your site's security certificate belongs to a different name — the certificate itself may be valid, but it was not issued for the exact address the visitor typed.
Common signs of this issue
- Chrome or Edge shows "Your connection is not private" with the code NET::ERR_CERT_COMMON_NAME_INVALID.
- Firefox shows "Warning: Potential Security Risk Ahead" with SSL_ERROR_BAD_CERT_DOMAIN, or Safari says the certificate is for a different website.
- The site works fine at www.yourdomain.com but shows the warning at yourdomain.com without the www, or the other way around.
- Clicking into the certificate details shows a name you do not recognize, such as your hosting company's server name or a completely different website.
- The certificate dates look fine and nothing has expired, yet browsers still refuse to trust the connection.
- The warning started right after moving hosts, adding a subdomain, changing DNS, or turning on a CDN or Cloudflare.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Try every version of your address: https://yourdomain.com, https://www.yourdomain.com, and any subdomain such as shop. or blog. Note exactly which ones show the warning and which load cleanly. That list alone usually points straight at the cause.
- Look at who the certificate was issued to. In most browsers, click the warning or the icon left of the address, open the certificate details, and look at the Subject Alternative Names list — that is the list of addresses the certificate covers. Modern browsers only check this list, so if your exact address is not on it, you get this error.
- If the name on the certificate is something like server123.yourhost.com or a shared hosting name, your host is answering for your domain but has no certificate set up for it yet. This is common right after a site move or when adding a new domain.
- If the certificate belongs to a completely different website, your domain is probably pointing at the wrong server — an old host, an old IP address, or a parked-domain service. Compare your domain's DNS records with the IP address your current host tells you to use.
- Run your domain through a free SSL checker such as Qualys SSL Labs' SSL Server Test. It shows which names the certificate covers and flags mismatches in plain terms, without you needing to change anything.
- In your hosting control panel, look for the SSL or AutoSSL / Let's Encrypt section and see which domains are listed as covered. Hosts often cover the main domain but skip www, or skip a domain that was added later.
- If you use Cloudflare, check the SSL/TLS section for your Edge Certificates. The free universal certificate covers your domain and one level of subdomain, so an address like a.b.yourdomain.com will not be covered.
What this usually means
An SSL certificate is like an ID card that lists the exact addresses it is allowed to vouch for. A name mismatch means the card is real and may be perfectly current, but the address in the visitor's browser is not on it. That is why owners are often confused: the certificate is valid, but it is not valid for this name, and browsers treat that as a possible impersonation and block the visit.
The most common cause for small businesses is the www versus non-www gap: the certificate was issued for one version of the domain and not the other, and some visitors, links, or old business cards use the missing version. Close behind is the host server certificate: after a move, a new domain, or a DNS change, the server answers with its own generic certificate because a certificate for your domain has not been issued yet. Less often, DNS is pointing at an old host or someone else's server entirely.
The fix is usually straightforward once the cause is clear: issue or reissue a certificate that includes every address people use, and make sure each of those addresses actually points at the current server, since free certificate services like Let's Encrypt can only issue for names that already reach your host. Then pick one preferred version of the domain and redirect the other to it. It is rarely a sign of a hack, but it does stop visitors cold until it is fixed.
What not to do
- Don't tell customers to click Advanced and proceed anyway. It trains them to ignore real security warnings, and many will simply leave.
- Don't buy an expensive certificate before checking what went wrong. Most mismatches are fixed with a free certificate that simply covers the right names.
- Don't delete the only working certificate while trying to fix the missing name. Add coverage first, then clean up.
- Don't change DNS records you do not understand. Pointing the domain at the wrong place can take down email as well as the website.
- Don't assume a redirect alone will fix it. The browser checks the certificate before it follows any redirect, so the address being redirected also needs to be covered.
When to get help
Most of the time your hosting company's support team can fix a name mismatch in minutes once you tell them exactly which address shows the warning and what name the certificate lists, so start there. It is worth bringing in outside help if the host insists the certificate is fine but visitors still see the error, if the problem appeared after a site move and involves DNS at a separate registrar, or if Cloudflare, a CDN, or several subdomains are in the mix. Those setups have more than one place a certificate can live, and someone who can trace which server is actually answering for each address can usually resolve it in one sitting instead of a week of back-and-forth tickets.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does ERR_CERT_COMMON_NAME_INVALID mean?
It means the website presented a security certificate, but the certificate was not issued for the address you visited. The certificate may be completely valid for another name, such as the www version of the domain or the hosting company's server, so the browser refuses to trust it for this one.
Why does my site work with www but not without it?
Your certificate probably covers only one version of the domain. The two addresses look almost identical to people, but to a browser they are different names, and each must be listed on the certificate. Reissuing the certificate to include both usually fixes it.
The certificate is valid, so why does the browser say it is not secure?
Being valid means the certificate is current and was issued by a trusted authority. Browsers also check that it was issued for the exact address in the address bar. A valid certificate for the wrong name still fails that check.
Is a certificate name mismatch a sign my site was hacked?
Usually not. It is almost always a setup gap, such as a missing www name, a certificate not yet issued after a host move, or DNS pointing at an old server. It is still worth fixing quickly, because visitors cannot tell the difference and will leave.
How long does it take to fix a certificate name mismatch?
Once the domain points at the right server, a free certificate can often be issued in minutes. If DNS changes are needed first, allow a few hours for them to take effect before the new certificate can be issued.
Do I need a wildcard certificate?
Only if you run many subdomains. Most small business sites need just two names covered, the bare domain and the www version, which standard free certificates handle fine.