Synthetic Industry

Job ssl-certificate-expired-not-secure · revised 9 October 2026

Clear the “Not secure” warning after your site's certificate expired

Find why your site’s HTTPS certificate expired, replace it through your host, check the renewal path where the host exposes it, and set an independent expiry warning.

You might be seeing

  • “Your connection is not private” or “Warning: Potential Security Risk Ahead” instead of your site
  • “Not secure” next to your address in the browser bar
  • Your host's panel shows AutoSSL or Let's Encrypt errors for the domain
  • The site works on one address, such as without www, but warns on the other

No passwords, keys, card details or admin invites needed to start.

What usually happened

The certificate that proves your site's identity has expired, or covers the wrong name, because automatic renewal quietly failed: the domain's DNS points somewhere the host can't verify, a redirect or firewall blocks the renewal check, or a certificate bought for a year was never renewed. Browsers then block visitors with a full-page warning.

Who it’s for: Owner of a small business website on shared or managed hosting, whose padlock disappeared and who has nobody technical to ask.

Usually starts when: Browsers start warning visitors “Your connection is not private” or show “Not secure”, often after a DNS change, a host move, a Cloudflare setting or a paid certificate's renewal date passing.

The result: Your domain with and without www serves a valid certificate and a tested expiry warning. We check the host’s renewal configuration and logs or a supported dry run; if future auto-renewal cannot be proved, we say so rather than promise it.

Check whether this job fits

Five questions, about two minutes. Your answers stay on this page unless you choose to email them.

What do visitors see?
How is the site hosted?
Is the domain itself paid up and in your name or your business's?

Your registrar's account, or a renewal email from them, shows the domain's expiry date.

Did anything change shortly before the warning started?
Is the warning on your own site's pages, or only on a booking, payment or shop page run by another company?

Answer the questions to see whether this job fits.

Nothing is sent anywhere until you choose to email us.

Email us your answers

Checks you can run yourself

  1. Read the certificate's dates and names

    Click the warning or the icon left of the address, then Certificate or Connection is not secure, then Certificate details. Or run this read-only check in a Mac or Linux terminal with your own domain.

    echo | openssl s_client -connect yourbusiness.co.uk:443 -servername yourbusiness.co.uk 2>/dev/null | openssl x509 -noout -dates -subject -ext subjectAltName

    Look for: The notAfter date, and whether the names listed include both your domain and the www version. A past date means it expired; a missing name means it doesn't cover that address.

  2. Look at your host's SSL page

    In your control panel, open SSL/TLS Status, AutoSSL or Let's Encrypt.

    Look for: An error next to your domain, such as a failed domain validation or DNS not pointing to this server. Screenshot it for us.

What you get

  • A note naming the cause, with the evidence
  • The exact fix steps, written for your host's support or your control panel
  • Before and after certificate checks for each agreed address
  • The expiry alert set up and sending to your address, and a test alert
  • Renewal-path check result or explicit note that the host does not expose a dry run or usable renewal log

Included

  • Finding why the certificate expired or doesn't match, from public checks and the renewal log your host shows you
  • Written fix steps for your host or you: a DNS record, a redirect rule, a panel setting or a certificate request
  • Checking the new certificate covers the domain and www and serves the full chain
  • Forcing visitors from http to https once the certificate is valid
  • An outside expiry check that emails you at least 14 days before the certificate ends
  • A check of the host’s renewal schedule, failure log or supported dry run; if the host exposes none, a documented limitation and outside alert

Not included

  • Rewriting pages that load images or scripts over http, beyond a list of what we find on the home page
  • Moving the site to another host
  • Servers you manage yourself without a control panel or host support: that needs a different job
  • Extended validation or organisation certificates bought from a certificate seller
  • Hacked-site recovery

How we know it’s done

Agreed with you before work starts. Each check produces evidence you keep.

  1. Each agreed address opens over https in a current browser with no certificate warning, and the certificate's names include that address

    Evidence: Certificate details and a screenshot per address

    curl -sSIv https://yourbusiness.co.uk/ 2>&1 | grep -E 'expire date|subject:|HTTP/'
  2. An independent public certificate test reports the full chain is served and the certificate is valid for at least 30 more days

    Evidence: Saved report from the test

  3. Requests to each address over http are redirected to https with a single redirect

    Evidence: Redirect check output per address

    curl -sI http://yourbusiness.co.uk/ | grep -i -E '^(HTTP|location)'
  4. The expiry alert is active for the domain and a test alert reaches your inbox

    Evidence: Screenshot of the alert's settings and the test email

  5. The host panel shows an enabled renewal schedule and its latest success or a supported dry-run result, or the handover explicitly marks future renewal unverified and relies on the tested expiry alert

    Evidence: Host renewal settings and redacted log or dry-run output; otherwise a dated unverified note and working alert

Sign-off. You sign off once the certificate, redirects and alert pass. The handover says whether a host renewal dry run or log was available; a current certificate alone does not prove it will renew next time.

If it fails. If the agreed certificate, HTTPS redirect or expiry-alert checks fail, you do not pay. You keep our findings to give to your host. Future automatic renewal is claimed only when the host exposes a successful test or log.

When it fits, and when we stop

It fits when

  • Your site is on hosting with a control panel, or a host whose support team will apply the steps
  • You can see or change where the domain's DNS points, or can say who can
  • The site loaded normally over https before the warning appeared, or you want https added on the same host
  • You can name the addresses that must work, such as with and without www

We stop and tell you if

  • The domain itself has expired or is held by someone who won't make changes
  • Signs of a hack, such as redirects to other sites or pages you didn't create
  • The host's plan doesn't allow any certificate, free or uploaded, and you don't want to change plan or host
  • The warning is for a page or service you don't control, such as a payment provider or a third-party booking widget

What could go wrong

Each step in the handover lists the setting or record before the change, so your host or you can put it back. Issuing a new certificate doesn't remove anything the site needs.

Scroll the table sideways to read it all.

RiskHow we handle it
A DNS change to fix the certificate breaks email or another service on the domainWe list every existing record first and change only the ones the certificate needs; the reviewer checks mail records are untouched.
Forcing https too early locks visitors out while the certificate is still invalidThe redirect is the last step, applied only after a valid certificate is confirmed on every agreed address.
The certificate renews now but fails again in a few monthsWe test renewal where the host exposes a test or verify a successful renewal log; otherwise renewal remains explicitly unverified. We configure and test an outside alert for at least 14 days before expiry.
Screenshots you send contain account detailsWe ask only for the SSL pages and delete screenshots after sign-off.

A second reviewer checks the cause and the fix steps, especially any DNS or redirect change that could take the site or email offline, before your host applies them.

How we deliver

We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.

  • Check the certificate, chain, DNS answers and redirect behaviour for each agreed address from outside
  • Compare that with the renewal error from your host's panel to name the cause
  • Write the fix steps for your host or you, and the order to apply them in
  • Independent review of the steps, especially any DNS change, before anything is applied
  • Your host or you apply the steps; we re-check every agreed address and test renewal where the host exposes it, recording any unverified renewal behaviour
  • Set up the outside expiry alert to your address and send a test alert

This is a one-off job, not emergency cover or a subscription. We confirm eligibility, the total price, a start window and a delivery date before you accept. Work starts only after agreed inputs, secure access, any licences and necessary permissions are in place. Hosting, platform and supplier charges are excluded unless the written quote includes them. No charge or booking is created by an enquiry.

Need to keep it working?

Discuss expiry-alert review and renewal checks if you need a standing responsibility rather than a one-off repair.

Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.

Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.

What you can check

This is a new service. We have not delivered this job for a client yet.

Other ways to get this done

  • Many hosts include free certificates and will re-run issuing if you ask their support with the error from the SSL page. Try that first: it often takes one ticket.
  • Free certificate checkers online show the expiry date and missing names, which is enough to tell your host what's wrong.

Questions

Do you need my hosting password?

No. We check your site from outside and work from the screenshots you send. Your host's support or you apply the steps.

Why did it stop renewing when it used to work?

Free certificates renew only if the host can prove the domain still points at it. A DNS change, a new Cloudflare setting or a redirect rule is the usual reason that proof fails.

Do I need to buy a certificate?

Usually not. Most hosts include free certificates. A paid one doesn't make visitors safer; it's mainly for organisations that need their name in the certificate.

Will this happen again?

Not guaranteed. We check the host’s renewal settings and logs or a supported dry run, and set an independent alert. If the host does not expose a renewal test, we say that future renewal is unverified.

Start with an email

Send us

  • Your site's address and any other addresses that should work, such as with www
  • A screenshot of the browser warning, including the error code if shown
  • Who hosts the site, and whether you use Cloudflare or a similar service in front of it
  • Anything that changed recently: DNS, nameservers, host, or a certificate renewal reminder you ignored
  • Any SSL or AutoSSL error your host's panel shows, as a screenshot

Later, once you agree

  • Screenshots of the panel's SSL/TLS page or the host's renewal log, as we ask for them
  • Confirmation from your host or you when each fix step is done, so we can re-check
  • A company-controlled secure handoff agreed before access: no live passwords, keys, private code or customer records by ordinary email.

You keep the hosting, domain and certificate accounts. AI agents check your site from outside and prepare the fix; a separate reviewer checks any DNS or redirect change. Your host or you apply the steps. Synthetic Industry is owned by a person and remains accountable for the agreed work.

Enquire — £149 fixed price

Or write to hello@syntheticindustry.ai with “ssl-certificate-expired-not-secure” as the subject.