ShieldWave

All articles

SSL certificate expiring: what to do before customers see a warning

How to read your certificate's expiry date, what visitors see once it lapses, why automatic renewal sometimes fails, and what to ask your hosting company.

Radek, ENSOMEDIAPublished 5 min readPo polskuبالعربية

The padlock next to your web address means your site has an SSL certificate. It is what keeps everything a customer types into your contact form or basket encrypted on its way to the server. Most owners never think about it, because for years it simply sits there and works.

Until the day it does not. A certificate has an expiry date, much like a passport. Once that date passes, browsers stop showing your site and show a full-page warning instead. Usually a customer notices before you do.

Checking your certificate takes about two minutes. Below is how to do it, what happens when a certificate expires, and what to ask your hosting company so that day never comes.

How to check the certificate yourself

Open your site in Chrome and click the icon to the left of the address. In recent versions it is no longer a padlock but a small icon with two sliders. Choose Connection is secure, then Certificate is valid.

In the window that opens, look for three things:

  • who the certificate was issued to, which should be your domain,
  • who issued it, for example Let's Encrypt, Sectigo or DigiCert,
  • the validity period, including the expiry date.

The free SSL certificate check shows the same, plus whether the certificate chain is complete and whether http redirects to https.

If there are several weeks left, there is nothing to worry about yet. Certificates that renew automatically are usually replaced around a month before they run out. If there are only a few days left and the certificate is still the old one, something in the renewal has failed and it needs reporting straight away.

What happens when a certificate expires

Your site does not vanish from the internet, but almost nobody will get to it. Chrome shows a screen that says Your connection is not private, with the code NET::ERR_CERT_DATE_INVALID. Firefox and Safari have their own versions of the same warning.

Technically, a visitor can click through the advanced details and carry on. Someone who only wanted to book an appointment or check your opening hours will not. They will close the tab and go back to the search results, where your competitors are one click away.

There are quieter effects too. Services that connect to your site automatically, such as a payment provider confirming that an order has been paid, may start reporting errors. Ads on Google or Facebook keep spending your budget, only now they send people straight to a warning screen.

The fix itself usually takes minutes. Your hosting company or developer issues a new certificate and the site is back to normal. The problem is that someone has to notice first, and if the certificate expires on a Friday evening, that can mean Monday morning.

Automatic renewal, and why it sometimes fails

Most hosting companies now issue free certificates from Let's Encrypt or a similar provider, and renew them automatically. A Let's Encrypt certificate lasts 90 days, so without automation nobody could keep up. Paid certificates are getting shorter as well. Since March 2026 no publicly trusted certificate can be valid for more than 200 days, and that limit is set to fall to 47 days by 2029. Renewing by hand once a year is on its way out.

Automation works well as long as nothing changes. The most common reasons it stops working:

  • the domain was moved to another server or put behind a proxy service, and the old hosting keeps trying to renew a certificate it can no longer verify,
  • someone added a redirect or a firewall rule that also blocks the address used to prove you own the domain,
  • the certificate was once bought by hand from another company and nobody set a reminder,
  • a paid renewal failed because the card on the account had expired.

One more change that few people heard about. In 2025 Let's Encrypt stopped sending expiry reminder emails. If anyone in your business was relying on "I'll get an email and deal with it then", that email is not coming any more.

Four addresses for one website

In practice your site has four addresses:

  • http://yourdomain.com
  • http://www.yourdomain.com
  • https://yourdomain.com
  • https://www.yourdomain.com

Type each one into the address bar by hand. All four should end up on one and the same https address. If any of them stays on plain http, forms on that version of the site send data unencrypted.

It also happens that the version without www works while the one with www shows a warning. That means the certificate covers only one of the two names. Chrome then reports NET::ERR_CERT_COMMON_NAME_INVALID.

This one is easy to miss, because you always type your address the same way. Meanwhile an old business card, an email signature or a directory listing may point people to exactly the other version.

The mixed content warning

Sometimes the certificate is perfectly valid and the browser still will not show a clean padlock. In Chrome you will see a note that your connection to the site is not fully secure. Sometimes a few images simply fail to load.

This is called mixed content. The page loads over https, but inside it some files are still requested over old http. It is usually left over from the switch to a certificate years ago: image addresses in old posts, a visitor counter script, a font or a partner's banner still point to http://. Browsers block those items or try to swap them, so the page looks slightly broken and your visitor sees a message that does not inspire confidence.

Fixing it is a job for your developer. They need to find every link that starts with http:// and change it to https://, both in the content and in the theme. On WordPress this is usually a single operation on the database, best done after taking a backup.

What to ask your hosting company

One email to your hosting company, or to whoever looks after the site, covers it:

  1. Does the certificate on our domain renew automatically, and who issues it?
  2. Does it cover both the www and the non-www version?
  3. Do all four versions of the address redirect to a single https address?
  4. Who gets notified if a renewal fails, and how quickly will they act on it?
  5. Is there any mixed content on the site?

You can add one small thing yourself. Put a reminder in your calendar two weeks before the expiry date you have just read. If on that day the certificate details already show a new, later date, the automation works. If not, you have two weeks to sort it out instead of an outage on a Friday night.