What to do if your SSL certificate expires (and how to stop it happening again)
When an SSL certificate expires, browsers show a full-page warning and nearly every visitor leaves. The good news: it takes minutes to fix. What matters is understanding why it failed so it doesn't happen again.
1. Confirm the certificate is the problem
Run your domain through our SSL checker. It shows the expiry date, the issuer and whether the name matches. If the certificate is valid but the name doesn't match, the issue is different: the domain or its www version wasn't included.
2. Renew it
On most hosting panels renewal is instant:
- Plesk: Websites & Domains, SSL/TLS Certificates, Let's Encrypt, Renew. Include aliases and the www version.
- cPanel: SSL/TLS Status or AutoSSL, then run the check.
- For a paid certificate, renew with your provider and reinstall it on the server.
3. Find out why auto-renewal failed
Free certificates last about 90 days and renew automatically unless something blocks it. The usual culprits: the domain no longer points to the server (check with the DNS tool), the .well-known folder is blocked by a rule or plugin, or the domain has aliases that weren't included.
4. Still seeing the warning after renewing?
Try a private window: your browser may cache the old warning. If you use a CDN like Cloudflare, make sure its SSL mode matches your certificate. And confirm with the HTTP headers tool that http redirects to https.
5. Make sure it never happens again
Set a reminder two weeks before expiry or, better, use a monitoring service that checks the certificate daily and alerts you before it lapses. Re-check the certificate after any DNS or server change.