Common causes
- Automatic renewal stopped. Let's Encrypt certificates last 90 days; a broken cron job or changed DNS makes renewal fail silently.
- Wrong name on the certificate. It covers
example.combut notwww.example.com, or the other way round. - Missing intermediate certificate. Works in one browser, fails in another or on mobile.
- Old server software offering only outdated TLS versions.
- A CDN or proxy presenting a different certificate than your server.
Check your certificate
Our free website security check reports whether the certificate is valid, how many days it has left and whether visitors are moved from HTTP to HTTPS. It also checks HSTS and mixed content, which cause browser warnings even with a valid certificate.
Fixing it
- Renew or reissue the certificate so it covers every hostname you use.
- Install the full chain, including intermediate certificates.
- Redirect all HTTP traffic to HTTPS and enable HSTS once everything works.
- Fix mixed content: images, scripts and styles still loaded over
http://. - Set up expiry monitoring so you are warned weeks in advance.
Frequently asked questions
Is a free certificate good enough?
Yes. Let's Encrypt and similar certificates provide the same encryption as paid ones. What matters is that renewal is automated and monitored.
Why does my site work on desktop but not on phones?
Usually a missing intermediate certificate. Desktop browsers sometimes fill the gap from cache; many mobile clients do not.
Does an SSL error hurt SEO?
Yes. Browsers block the page, visitors bounce and search engines may drop or demote pages they cannot load securely.