Why Does My Website Say 'Not Secure'? SSL Certificates in Plain English
Your browser suddenly says your website is not secure, with no warning and no explanation. Here is what that actually means, why it happened, and how to check yours free.
Nobody eases you into this one. One morning your website looks exactly as it did yesterday, except the browser has put the words Not secure next to your address — or worse, thrown a full-screen red warning that a visitor has to click past to reach you.
Nothing was hacked. In most cases nothing was even touched. Something expired, and the internet noticed immediately.
Here is what the warning means, in plain English, and what to do about it today.
What the padlock actually promises
That padlock is not a review of your business. It certifies two narrow things:
- The connection is encrypted. What a visitor types on your site — a contact form, a password, a card number — travels in a form nobody sitting between you can read.
- The site is who it claims to be. A certificate issued for your domain, by an authority browsers trust, is evidence that this really is your website and not somebody's convincing copy.
That is the whole promise. A padlock does not mean a site is honest, well built, or safe to buy from. Scam sites have padlocks; certificates are complimentary and quick to obtain, which is a good thing, because the alternative was a web where encryption was a luxury purchase.
What matters for you is the other direction. The absence of a padlock says something loudly, and visitors have been trained for a decade to believe it.
The three reasons you are seeing the warning
Almost every "not secure" comes down to one of these.
Your certificate expired. Certificates are deliberately short-lived — months, not years — so that a compromised one cannot be abused indefinitely. They are meant to renew automatically. When the renewal quietly fails, or when nobody set one up because the site was built as a one-off three years ago, the certificate simply runs out. The site does not change. The browser's verdict changes.
The certificate does not cover the address people are using. A certificate is issued for specific names. A very common version of this: the certificate covers example.com but not www.example.com, so half your visitors are fine and half get the warning, which makes the problem sound imaginary when someone reports it.
The page is loading something over an insecure connection. This is the sneaky one. Your certificate is valid, everything is configured correctly, and one image, font, or script somewhere on the page is still being fetched the old, unencrypted way. Browsers treat the whole page as compromised. Usually it appears after a redesign, or when an old plugin points at a hard-coded address.
There is a fourth, rarer case worth naming: the certificate is valid but issued by something the browser does not trust, which produces the loudest warning of the set. That one needs a person to look at it.
Why it is worth fixing this week
The warning is not cosmetic, and it does not wait politely.
Visitors leave. Most people do not read the message; they see red, assume they typed something wrong or that your business is in trouble, and go back. Forms stop being filled in, which means the loss shows up as silence rather than as a complaint. Search engines have treated encryption as a baseline expectation for years. And if you take payments or collect any personal information at all, an expired certificate is not just embarrassing — it is a genuine gap.
The good news is that this is one of the shortest distances between a problem and a fix on the whole internet.
How to check yours in about a minute
You do not have to guess which of the three it is.
Run the SSL Checker on your domain. It reads your certificate the way a browser does and tells you who issued it, which names it covers, whether it is currently valid, and exactly when it expires. Complimentary, no signup. Station 05 in the Tool Shed, if you are the sort who likes knowing where things hang.
Two numbers to look at when it comes back. Is it valid right now, and how many days until it expires. If the answer to the second is under thirty and nothing is set to renew it automatically, you have found next month's emergency early, which is the best possible outcome from a one-minute check.
If the certificate looks healthy but the warning persists, you are almost certainly in the third case — something on the page loading insecurely — and the Security Headers Checker is a reasonable next stop for a broader read on how the site is served.
How each one gets fixed
Expired: renew it, and then find out why the automatic renewal did not happen — otherwise you are booking the same morning again in three months. This is the fix people do halfway.
Wrong names: reissue the certificate to cover every address people actually use, www and bare domain both, and redirect one to the other so there is a single answer.
Insecure content on the page: track down what is loading the old way and repoint it. On WordPress this is usually a plugin, a theme setting, or old links stored in the database from before the site moved.
None of the three is exotic. All three are the kind of thing that sits undone for months because it belongs to nobody.
The version where you never think about it again
Here is the honest position: certificate renewal is a solved problem, and any hosting worth paying for should have solved it on your behalf. It is a scheduled task that a machine should run, not a date a business owner should remember.
That is how our hosting works. SSL is issued and renewed automatically on every site, on every plan, with no add-on and no renewal date for you to diarise. If your site lives somewhere else, the checker above still works on it, and you should absolutely use it — this is not a problem you need to move house to solve. But you should not be finding out about it from a customer, either.
Go and look. Run the SSL Checker on your own address, and while you are there, on the www version too. It takes a minute, and the most common result is the reassuring one: valid, trusted, renewing on its own, nothing to do.