A guide, free to read

Why your website says "Not secure"

A customer calls and says your website is showing a warning. You open it on your laptop while they are still on the phone. It looks perfectly normal. Padlock in the corner, everything loading, nothing red anywhere.

So you tell them it must be their end, and you both move on.

It is almost never their end. The usual reason a site looks fine to you and broken to them is that you are not looking at the same thing. Here is why that happens, what your customers are actually seeing, and how to check it properly.

You are not imagining the mismatch, and neither are they

This is common enough that owners post about it in the same words. One shop owner wrote:

"I have had multiple customers telling me they are not able to access our website, however, when I check, it is telling me it is secure."

Another opened a thread with the word "Urgent" in the title and said the message had been appearing for almost three months. Several customers had reported it. She had checked it herself, repeatedly, and seen nothing wrong. It came, in her words, "out of the blue one day", and it had "significantly impacted sales".

Three months of lost customers, on a problem she could not see.

That is the whole difficulty with this one. A broken lock on a shop door is obvious the moment you touch it. A security warning on a website is invisible to the one person who could fix it.

What your customers actually see

It is worth knowing the exact words, because customers rarely describe it accurately. They say "your site's down" or "it said something about a virus".

Chrome and Edge put the words Not secure to the left of your web address. Some people notice it. Many do not.

Worse is the full page warning. Instead of your site they get a plain screen with a large heading and a button to go back. Chrome says "Your connection is not private". Safari says "This Connection Is Not Private". Firefox says "Warning: Potential Security Risk Ahead".

That full page one is the business problem. There is no site behind it, only a gray screen and a warning about your company. Most people leave. A few will assume you were hacked.

The six things that cause it

Roughly in order of how often they turn out to be the answer.

One. Your certificate covers one version of your address and not the other.

yourbusiness.com and www.yourbusiness.com look like the same thing to a human. To a certificate they are two different names, and a certificate has to list both.

You always type it the same way, probably without the www, so you never see the problem. Customers arrive from a Google result, an old business card, a Facebook post from 2021, and half of them land on the other one.

This is the single most common version of "fine for me, broken for them", and it is invisible by design.

Two. Your certificate expired.

Certificates have end dates. Most are automatic now and renew themselves every 90 days, quietly, forever.

Until one time the renewal fails. Nothing tells you. There is no email, no alert, no red mark on your dashboard. The site carries on working for the rest of that certificate's life and then one morning it does not. The owner above described it exactly: out of the blue, one day.

Three. One thing on the page is loading the old, insecure way.

Your page is secure, but something inside it is not. Usually an image, an old font, a tracking snippet, or a map somebody embedded years ago.

Browsers treat a page like that as compromised and take the padlock away, or block the item outright so part of your page is simply missing.

The reason this one is so slippery is that it happens per page. Your home page can be perfect while your contact page throws a warning, because the contact page has an old embedded map on it and the home page does not. You check the home page. You always check the home page.

Four. Your site never sends people to the secure version.

If somebody types your address without https at the front, a properly set up site quietly moves them across to the secure version. If that redirect was never turned on, they stay on the insecure one and get the warning.

Your own browser remembers the secure version from last time and takes you there automatically. Theirs has never been, so it does not.

Five. The customer is on an old phone or an old computer.

Genuinely their end, but still worth knowing. Old Android phones and old Windows machines stop trusting newer certificates because they have not been updated in years.

You cannot fix this and you should not try. But if the complaints are all from one person with a seven year old phone, that is the explanation.

Six. They are on a network that inspects traffic.

Office wifi, hotel wifi, some school and hospital networks. The network puts itself in the middle and the browser objects, correctly.

Also not your fault, also not fixable by you.

How to actually check, since your own browser lies to you

Your laptop is the worst possible place to test this. It has been to your site a hundred times, it remembers the secure version, and it may still be holding a certificate that has since expired.

Check both versions of your address. Type https://yourbusiness.com and then https://www.yourbusiness.com and look at each. If one is fine and the other warns you, you have found cause number one and you are most of the way to fixing it.

Check on your phone with wifi switched off. Different device, different network, no memory of your site. This is the closest you can get to being a stranger.

Check more than the home page. Open your contact page, your services page, anything with a map or a video on it. Cause number three lives on exactly those pages.

Run a free certificate checker. Search for "SSL checker", put your address in, and read two things: the expiry date, and the list of names the certificate covers. That list is where you confirm whether both the www and non-www versions are included.

Ask one person. Text somebody who has never visited your site and ask them to open it and say what they see. Thirty seconds, and it is better evidence than anything you can do from your own desk.

What to do once you know which one it is

Expired certificate. If you are on Wix, Squarespace, Shopify or GoDaddy's builder, this is theirs to fix and it is usually free. Contact support and use the phrase "my SSL certificate has expired". On WordPress it is your host's job, same phrase.

Only one version covered. Ask your host or your developer to make the certificate cover both yourbusiness.com and www.yourbusiness.com, and to redirect one to the other so there is only ever one real address. On most modern hosting both are a settings change, not a project.

Something loading the old way. Someone needs to find the offending item and update it. It is usually a five minute job once found, and the finding is the slow part. Tell whoever does it which page it happens on.

No redirect to the secure version. A single setting on nearly every platform, often labeled "force HTTPS" or "always use secure connection".

Do not accept "it looks fine to me" as an answer from anyone, including yourself. That sentence is how three months went by for the owner quoted at the top of this page.

Do you actually need a certificate?

Yes, and the reasons have nothing to do with how sensitive your website is.

People ask this because they run a five page site with no payments and no logins, so they reasonably wonder what there is to protect.

It is not really about protection any more. Browsers now mark every site without one as Not secure, whatever is on it. A plumber's site with three photos and a phone number gets the same warning as a bank. Your visitor does not stop to ask what data was at risk. They see a warning about your business and they leave.

Certificates are also free. Let's Encrypt gives them away and every serious host includes one. If somebody is charging you extra for basic SSL, ask them why.

The part worth setting up once

Certificates renew every 90 days on their own, and the failure is silent by nature. Nobody finds out from their host. They find out from a customer, weeks later, if they are lucky.

So set a reminder in your calendar for the first of every month, thirty seconds long: open your site on your phone with wifi off, and open the www version too. That is it.

It feels like too small a thing to bother with. It is also the difference between hearing about this in the first week and hearing about it in the third month.

All fifteen guides

Coming soon

A website checker that tells you what is wrong with your site, in plain English.