Help centre

Why the browser says a site is “not secure”

Short answer

The browser warns when it can’t confirm a secure connection: the certificate has expired, is missing, was issued for a different name, or the page loads unprotected elements. The problem is almost always the site’s SSL certificate, not your browser.

Source: ZRAZU rules on certificate status; CA/Browser Forum rules

The most common reasons

  • The certificate expired — The certificate’s validity ran out and automatic reissuing either failed or isn’t set up.
  • There’s no certificate at all — The site has no certificate installed yet — the connection runs over unencrypted http.
  • The name doesn’t match — The certificate was issued for a different domain name, or doesn’t cover the subdomain (like www.) being opened.
  • Unprotected content — An https page loads an image or script over http — the browser treats the connection as partly unprotected.

How to check it yourself

The certificate-check tool shows the validity period, the chain, which name the certificate was issued for, and whether there’s a mismatch.

Check a site’s certificate

FAQ

Can this be fixed for free?

Yes: Let’s Encrypt is a free certificate that’s enough to encrypt any site; the difference from paid ones isn’t encryption strength.

Why didn’t the warning disappear right after installing the certificate?

The browser and intermediate caches may remember the previous state for a while; try a hard refresh or open the site in another browser.

Did this article help?