Australian Website Design Measured figures. Named sources.
Menu Close

Diagnostics

My SSL certificate has expired

An expired SSL certificate triggers the browser warning that frightens customers — usually a fifteen-minute fix, and how to stop it recurring.

In short. An expired certificate is not an outage: the site is running and the browser is refusing to display it without a full-page warning. It is almost always a renewal that did not run rather than a security incident, and on most hosting it is fixed within the hour. The damage is to trust, and it is immediate.

An expired SSL certificate is not an outage. The website is running normally and the browser is refusing to display it without a full-page interruption telling the visitor the connection is not private.

In commercial terms that is close enough to down. It is worse in one respect: a site that fails to load looks like a technical problem, while an SSL security warning looks like the business cannot be trusted. Customers do not read the detail.

It is also, almost always, an SSL certificate renewal that did not run, rather than a security incident.

What an SSL/TLS security certificate actually does

An SSL certificate does two things, and is widely believed to do a third.

It encrypts the connection between the visitor and the server, so that what is typed into a form cannot be read in transit. And it identifies the domain, so the browser can confirm it is talking to the site it asked for.

An SSL/TLS certificate does not verify that the business is legitimate, reputable or safe to deal with. A padlock means the connection is encrypted, not that the operator is honest. That distinction matters because “we have SSL” is sometimes offered to customers as a trust claim, and it is not one.

Why the SSL certificate expired: certificate expiration and validity

CauseFrequencyFix
Automatic renewal failed to runMost commonTrigger it, or repair the process
The domain moved and the certificate did notCommon after a migrationReissue on the new host
A paid certificate lapsed with the invoiceOccasionalPay and reinstall
DNS validation stopped workingOccasionalRestore the record, reissue
Installed for one hostname, used on anotherOccasionalReissue covering both

The last row is a specific and confusing case: the site works at www.example.com.au and warns at example.com.au, or the reverse, because the certificate covers one and not the other. It looks intermittent and it is not — it depends which address the visitor used, which is one of the reasons to settle on a single canonical address, covered on canonical addresses.

The fix: how to renew an expired SSL certificate

On most modern hosting, SSL certificates are issued and renewed automatically at no cost. The fix is to find the setting in the hosting control panel and trigger a renewal, or work out why the automatic renewal process stopped. This is usually a support ticket that resolves in minutes, and hosts handle SSL certificate renewal constantly.

On a paid SSL certificate, it is a purchase, an issue and an installation — sometimes generated from a CSR (certificate signing request) — which takes longer and involves whoever administers the server.

In both cases the question afterwards is why nobody knew. A certificate has a fixed expiry date, that date is known months in advance, and the renewal notice went somewhere. Where it went is the actual finding.

While it is broken

Two things worth doing immediately, neither of them technical.

Pause any paid advertising pointing at the site. Every click is landing on a security warning, which is money spent producing a negative impression.

Do not tell customers to click through the warning. Teaching people to bypass browser security warnings is bad advice generally and it will be remembered as coming from you.

A page can show a warning while the certificate is perfectly valid, when the page loads some of its content over an insecure connection. It usually appears after content is added — an image, a script or an embed referenced with an insecure address.

The symptom is different: not a full-page interruption but a downgraded indicator, or an element of the page that fails to appear. The fix is to correct the reference rather than the certificate, and it is worth knowing the difference before calling anyone.

Preventing the repeat: certificate renewal and expiry monitoring

Confirm renewal is automatic, and confirm it by watching one renewal succeed rather than by being told it is.

Send expiry notices to an address the business monitors. The pattern here is identical to domain expiry: the notice went to a former staff member, a supplier, or an inbox nobody opens. That pattern is covered on an expired domain.

Put the expiry date in a calendar owned by the business, thirty days ahead.

Check it after any migration. Certificates are attached to servers, and moving servers is the second most common cause on the table above. A migration that goes smoothly in every other respect will still leave this one to fail a fortnight later.

Include it in whatever monitoring exists. Most uptime monitoring will report a certificate expiring days in advance, and it is usually a checkbox nobody ticked.

Whose job renewing SSL certificates and certificate expiry is

On managed hosting, the host’s, and it should be stated as such in what you are buying. On a self-managed server, whoever administers it. Where an agency holds the hosting account on your behalf, it is theirs. This is one of the items worth naming explicitly in a maintenance arrangement, rather than assuming — because it sits exactly on the boundary between hosting and maintenance where things go unowned. What such an arrangement should contain is on what website maintenance actually is.

A short recap on SSL certificates, expiry and renewal

An SSL/TLS certificate has a validity period, and when that period ends the certificate expires. Expiration is the trigger for every symptom on this page: the warning, the lost trust, the paid clicks landing on a security message instead of a page. Renewal resets the validity period before expiry happens, which is why most certificate expiration incidents are really a renewal that silently failed to run, not a genuine security problem with the certificate itself.

What to do next

Load your own site and look at the address bar. Then find out today whether renewal is automatic and where the expiry notice is sent. Both take five minutes and between them they prevent the whole category. If the answer to “who handles that” is unclear, that is the larger finding, and what a website design company actually is covers how that responsibility is usually divided.

Evidence for this page

This page exists because the demand below was measured, not assumed. The figures are search-market data about the topic — they are not prices.

Entity this page targets
expired ssl certificate
Measured Google volume
no data
Keyword difficulty
no data
Advertiser cost per click
no data
AI assistant volume
no data
Advertiser competition
no data
Measured on
31 July 2026
Search results inspected for intent
No
3 other phrasings resolve to this same page

your connection is not private warning · website security certificate expired · https not working on my site

Absent from the measured Australian universe in research/national-volume-au.json. What a certificate is and does is explained in the hosting guides; this page is for somebody looking at the warning right now, which is a different need.

Source: research/national-volume-au.json · DataForSEO Labs, location_code 2036 (Australia), language en · pulled 31 July 2026.

Provenance

Written by Australian Website Design. Published 2026-08-04, last updated 2026-08-04.

Sources

  • National keyword volume and difficulty, Australia — research/national-volume-au.json (accessed 2026-07-31)