I forgot to renew my certificate and now it says "certificate expired" — how do I fix it fast?
A red "certificate expired" screen? Your site is intact. Here are the fast steps to renew your SSL certificate and bring the padlock back.
You just opened your site and, instead of the padlock, you see a red screen: "Your connection is not private" or "certificate expired." Your stomach drops — it looks like your whole site vanished overnight. The good news: nothing vanished. Your files, text and images are exactly where you left them.
What actually happened is far more mundane than it looks: an "ID document" that tells browsers your connection is encrypted has expired. You renew it, and in most cases the problem is solved in a few minutes to an hour. Below are the exact steps, in order, depending on where your site is hosted — plus how to make sure it doesn't happen again.
Breathe: your site is intact, only the certificate expired
An SSL/TLS certificate is the "ID document" that tells a browser the connection to your site is encrypted. Every such certificate has an expiry date — free Let's Encrypt ones are valid for 90 days, paid ones usually for a year. Once that date passes, the browser can no longer vouch for the connection and shows the red warning.
What this means in practice:
- Your files, text and images are intact on the server.
- You weren't hacked and you haven't lost anything.
- Visitors can technically still reach the site, but many are scared off by the red screen and leave.
So this isn't an "I lost everything" emergency — it's a "renew a document" one. That's exactly why it's worth fixing quickly, but without panic.
The first 5 minutes: confirm what you see and who issues your certificate
Before you call anyone, gather three pieces of information — they'll shorten the whole process:
- The exact error text. "NET::ERR_CERT_DATE_INVALID" clearly means an expired certificate. "ERR_CERT_COMMON_NAME_INVALID" is a different problem (a certificate issued for another domain), so don't treat it the same way.
- The expiry date. Click "Not secure" / the padlock → "Certificate" and look for "Valid until." Confirm it really has expired rather than something else being wrong.
- Who issues your certificate. Usually the same place your site is hosted: a cPanel host, a modern provider like Vercel or Netlify, a platform like WordPress.com or Wix, or Cloudflare sitting in front.
Also check whether the error shows only on "www" or only on the bare domain — sometimes just one certificate is missing, not both.
The fast fix, depending on where your site is hosted
The steps differ based on who manages the certificate:
- All-in-one platforms (WordPress.com, Wix, Shopify, Squarespace): you don't touch the certificate, it renews itself. If it expired anyway, it's almost certainly something to do with the domain or DNS. Log in, check the domain is still connected correctly, and open a support ticket — they'll reissue it quickly.
- Vercel / Netlify and modern hosts: certificates are automatic. An expiry usually means changed DNS. Check your domain records and force a reissue from the dashboard.
- cPanel / classic host: look for "SSL/TLS Status" or "AutoSSL," select the domain and click "Run AutoSSL" to regenerate the Let's Encrypt certificate.
- Paid certificate: you have to buy it again from the provider and reinstall the files — the slowest step, but still doable the same day.
Why the automatic renewal broke
The most common reasons auto-renewal stops working:
- The domain was moved or DNS records changed, so the validation process can no longer find the site.
- A redirect (for example forcing HTTPS) blocks the "challenge" that Let's Encrypt uses to confirm the domain is yours.
- The hosting plan or the domain expired in the meantime — the certificate falls with it.
- A CAA record on the domain forbids the authority that used to issue the certificate.
You don't need to fix all of these by hand. The key thing to understand is that if "automatic" renewal failed once, it will fail again until the underlying cause is resolved. That's why the prevention step below genuinely matters — otherwise you'll be staring at the same red screen three months from now.
Test it properly and clear the cache
Once you've reissued the certificate, don't trust your first impression:
- Open the site in an incognito window or on your phone over mobile data. Your browser may have cached the old certificate and be scaring you for nothing.
- Test both "https://yourdomain.com" and "https://www.yourdomain.com".
- Use an online SSL checker (search "SSL checker") to confirm not only that the certificate is valid, but that the certificate "chain" is complete — a missing intermediate certificate produces the same error face on some devices.
If you still see red after a few minutes, the renewal either hasn't propagated yet or didn't succeed. Repeat the step in the dashboard, or write to your host's support with the exact error text pasted into the message.
So it never happens again (and where to get a hand)
So you never relive this panic:
- Enable automatic renewal and verify once that it actually works — don't assume, test.
- Set a calendar reminder a few weeks before paid certificates expire.
- Ideally, move the site to infrastructure where TLS renews itself in the background, without it being your job.
At MPO Web Studio we build and host sites on infrastructure where the certificate renews automatically — you simply stop seeing "certificate expired." We work entirely remotely, across the whole country, with transparent pricing, and we can prepare a ready-built demo of your site in advance before you pay anything. If you're stuck with the red screen right now and want help, message us on WhatsApp — we'll look together and tell you honestly what's a five-minute fix and what depends on your current host.
Frequently asked questions
Does my site lose its Google ranking while the certificate is expired?+
A few hours of expiry rarely moves rankings. The real problem is that visitors see the red screen and leave, and if the state lasts for days, Google may start flagging the site as unsafe. Fix it quickly and things return to normal.
Is a free certificate weaker than a paid one?+
Not in terms of encryption — a free Let's Encrypt certificate encrypts just as well as a paid one. The difference is validity (90 days versus a year) and, on some paid certificates, extra company validation. For most brochure-style sites, the free one is perfectly fine.
How long until the warning disappears after renewal?+
Usually a few minutes. If you still see it, clear the cache or test in incognito — most often it's your browser holding onto the old certificate, not the site itself.
Can I fix it myself or do I need someone technical?+
It depends on the host. On a modern platform or with AutoSSL in cPanel, it's a button you press yourself. If it's a paid certificate to reinstall or DNS to repair, it's more comfortable with someone technical beside you.
Why did it expire if it "renewed automatically"?+
Almost certainly something broke the validation — changed DNS, a redirect, or an expired host/domain subscription. Automation assumes everything stays stable; when something changes, it stops quietly. That's why it's worth verifying once, not just assuming.
7 mistakes that drive clients away from your website
Leave your email and get the guide right here, instantly. No spam.
Want to see what your business's website could look like?
Message us on WhatsApp and we'll build you a free demo website with your business name on it. See it first, then decide — no strings attached.