Diagnostics
My SSL certificate has expired
An expired SSL certificate triggers the browser warning that frightens customers — usually a fifteen-minute fix, and how to stop it recurring.
In short. An expired certificate is not an outage: the site is running and the browser is refusing to display it without a full-page warning. It is almost always a renewal that did not run rather than a security incident, and on most hosting it is fixed within the hour. The damage is to trust, and it is immediate.
An expired SSL certificate is not an outage. The website is running normally and the browser is refusing to display it without a full-page interruption telling the visitor the connection is not private.
In commercial terms that is close enough to down. It is worse in one respect: a site that fails to load looks like a technical problem, while an SSL security warning looks like the business cannot be trusted. Customers do not read the detail.
It is also, almost always, an SSL certificate renewal that did not run, rather than a security incident.
What an SSL/TLS security certificate actually does
An SSL certificate does two things, and is widely believed to do a third.
It encrypts the connection between the visitor and the server, so that what is typed into a form cannot be read in transit. And it identifies the domain, so the browser can confirm it is talking to the site it asked for.
An SSL/TLS certificate does not verify that the business is legitimate, reputable or safe to deal with. A padlock means the connection is encrypted, not that the operator is honest. That distinction matters because “we have SSL” is sometimes offered to customers as a trust claim, and it is not one.
Why the SSL certificate expired: certificate expiration and validity
| Cause | Frequency | Fix |
|---|---|---|
| Automatic renewal failed to run | Most common | Trigger it, or repair the process |
| The domain moved and the certificate did not | Common after a migration | Reissue on the new host |
| A paid certificate lapsed with the invoice | Occasional | Pay and reinstall |
| DNS validation stopped working | Occasional | Restore the record, reissue |
| Installed for one hostname, used on another | Occasional | Reissue covering both |
The last row is a specific and confusing case: the site works at www.example.com.au and warns at example.com.au, or the reverse, because the certificate covers one and not the other. It looks intermittent and it is not — it depends which address the visitor used, which is one of the reasons to settle on a single canonical address, covered on canonical addresses.
The fix: how to renew an expired SSL certificate
On most modern hosting, SSL certificates are issued and renewed automatically at no cost. The fix is to find the setting in the hosting control panel and trigger a renewal, or work out why the automatic renewal process stopped. This is usually a support ticket that resolves in minutes, and hosts handle SSL certificate renewal constantly.
On a paid SSL certificate, it is a purchase, an issue and an installation — sometimes generated from a CSR (certificate signing request) — which takes longer and involves whoever administers the server.
In both cases the question afterwards is why nobody knew. A certificate has a fixed expiry date, that date is known months in advance, and the renewal notice went somewhere. Where it went is the actual finding.
While it is broken
Two things worth doing immediately, neither of them technical.
Pause any paid advertising pointing at the site. Every click is landing on a security warning, which is money spent producing a negative impression.
Do not tell customers to click through the warning. Teaching people to bypass browser security warnings is bad advice generally and it will be remembered as coming from you.
The related warning that is not an expiry
A page can show a warning while the certificate is perfectly valid, when the page loads some of its content over an insecure connection. It usually appears after content is added — an image, a script or an embed referenced with an insecure address.
The symptom is different: not a full-page interruption but a downgraded indicator, or an element of the page that fails to appear. The fix is to correct the reference rather than the certificate, and it is worth knowing the difference before calling anyone.
Preventing the repeat: certificate renewal and expiry monitoring
Confirm renewal is automatic, and confirm it by watching one renewal succeed rather than by being told it is.
Send expiry notices to an address the business monitors. The pattern here is identical to domain expiry: the notice went to a former staff member, a supplier, or an inbox nobody opens. That pattern is covered on an expired domain.
Put the expiry date in a calendar owned by the business, thirty days ahead.
Check it after any migration. Certificates are attached to servers, and moving servers is the second most common cause on the table above. A migration that goes smoothly in every other respect will still leave this one to fail a fortnight later.
Include it in whatever monitoring exists. Most uptime monitoring will report a certificate expiring days in advance, and it is usually a checkbox nobody ticked.
Whose job renewing SSL certificates and certificate expiry is
On managed hosting, the host’s, and it should be stated as such in what you are buying. On a self-managed server, whoever administers it. Where an agency holds the hosting account on your behalf, it is theirs. This is one of the items worth naming explicitly in a maintenance arrangement, rather than assuming — because it sits exactly on the boundary between hosting and maintenance where things go unowned. What such an arrangement should contain is on what website maintenance actually is.
A short recap on SSL certificates, expiry and renewal
An SSL/TLS certificate has a validity period, and when that period ends the certificate expires. Expiration is the trigger for every symptom on this page: the warning, the lost trust, the paid clicks landing on a security message instead of a page. Renewal resets the validity period before expiry happens, which is why most certificate expiration incidents are really a renewal that silently failed to run, not a genuine security problem with the certificate itself.
What to do next
Load your own site and look at the address bar. Then find out today whether renewal is automatic and where the expiry notice is sent. Both take five minutes and between them they prevent the whole category. If the answer to “who handles that” is unclear, that is the larger finding, and what a website design company actually is covers how that responsibility is usually divided.
Evidence for this page
This page exists because the demand below was measured, not assumed. The figures are search-market data about the topic — they are not prices.
- Entity this page targets
- expired ssl certificate
- Measured Google volume
- no data
- Keyword difficulty
- no data
- Advertiser cost per click
- no data
- AI assistant volume
- no data
- Advertiser competition
- no data
- Measured on
- 31 July 2026
- Search results inspected for intent
- No
3 other phrasings resolve to this same page
your connection is not private warning · website security certificate expired · https not working on my site
Absent from the measured Australian universe in research/national-volume-au.json. What a certificate is and does is explained in the hosting guides; this page is for somebody looking at the warning right now, which is a different need.
Source: research/national-volume-au.json · DataForSEO Labs, location_code 2036 (Australia), language en · pulled 31 July 2026.
Provenance
Written by Australian Website Design. Published 2026-08-04, last updated 2026-08-04.
Sources
- National keyword volume and difficulty, Australia —
research/national-volume-au.json(accessed 2026-07-31)