Why Browsers Warn About Your Site (and How to Fix It)
A browser warning on your own website feels alarming, and it should get your attention, but most warnings have ordinary causes and straightforward fixes. This article explains what the common warnings mean, how to fix each one, and when the problem is on the visitor’s side rather than yours.
Warning: certificate expired
This means the certificate’s validity period has ended. Browsers treat an expired certificate as untrustworthy, even if everything else is fine. If you use the free automatic SSL on your InterProWebHost hosting, renewal normally happens on its own. An expired certificate usually means auto renewal failed, often because DNS was changed or the domain stopped pointing at the hosting. Check that your domain still resolves to your account, then run the AutoSSL check in cPanel under SSL/TLS Status. For paid certificates, check the expiry date in your client area and renew before it lapses. Set yourself a reminder a month before the next expiry.
Warning: certificate name mismatch
The browser expected a certificate for your domain but got one issued for a different name. The classic cause is a certificate that covers yourbusiness.com but not www.yourbusiness.com, or vice versa. Visitors using the uncovered version see a warning. The fix is a certificate that covers both versions, which the automatic free SSL normally does. If you bought a paid certificate, check exactly which names it covers and reissue it with both the www and non-www versions included.
Warning: parts of the page are not secure (mixed content)
The page loads over HTTPS, but some images, scripts, or stylesheets still load over plain HTTP. Browsers may block those parts or show a warning. This is the most common SSL issue on established sites, and it usually appears after SSL is newly installed on a site built without it. The fix is to find the http references and change them to https. In WordPress, check Settings, General first, then look through widgets, theme settings, and page content for hardcoded http links to your own domain. After fixing, reload the page and confirm the padlock is clean on every page, not just the homepage.
Warning: your connection is not private (generic)
This is the browser’s general message for several certificate problems, including expired, mismatched, and self-signed certificates. Click the advanced details in the warning; the browser usually names the specific problem, such as an expired certificate or an untrusted issuer. Match what it says to the sections above. A self-signed certificate, one the server generated for itself rather than from a recognized authority, always triggers this warning for visitors. Replace it with a proper certificate using How to Install a Free SSL Certificate.
When the problem is the visitor, not your site
Sometimes your site is fine and the warning comes from the visitor’s side. An incorrect date and time on their computer makes certificates appear expired. Very old browsers and operating systems may not recognize modern certificate authorities. Corporate and school networks sometimes intercept secure connections with their own certificates, which triggers warnings. If only one person reports a warning and everyone else sees the padlock, ask them to check their system clock and try a different browser before you change anything on the site.
A quick diagnostic routine
- Open the site yourself in a private browser window. Note the exact warning wording.
- Check the certificate details by clicking the padlock or warning icon: look at the expiry date and the domain names listed.
- In cPanel, open SSL/TLS Status and confirm a valid certificate is installed for the domain.
- Check several pages for mixed content, not just the homepage.
- If everything looks right on your side, test from your phone on mobile data to rule out a local network issue.
Still stuck? Open a support ticket with your domain name and the exact warning text, or a screenshot of it. The exact wording tells us precisely where to look.