Your SSL (more precisely TLS) certificate is what puts the padlock in the browser and lets your site load over https://. Every certificate has an end date. When that date passes, your website doesn't go down, but it might as well have.

What visitors see

Instead of your homepage, every browser shows a full-page warning such as "Your connection is not private" (Chrome, error NET::ERR_CERT_DATE_INVALID) or "Warning: Potential Security Risk Ahead" (Firefox). To continue, a visitor has to click through "Advanced" and accept the risk. Almost nobody does.

It goes further than lost visitors:

  • Online payments and forms stop working, because payment providers and browsers refuse insecure connections.
  • Apps and integrations that call your site (booking widgets, mobile apps, webhooks) fail with errors.
  • Your mail server may use a certificate too. If it expires, some email clients can't connect.
  • Customers lose trust. A security warning on a business website looks like a hacked website.

"But my certificate renews automatically"

Most sites today use free certificates from Let's Encrypt (directly or through their host), which last 90 days and renew themselves at about 30 days before expiry. That works well, until something quietly breaks it:

  • DNS or hosting changed. The domain now points somewhere the renewal can't reach, or the site moved to a new server and the old one was doing the renewing.
  • A CDN, firewall or security plugin blocks the request Let's Encrypt uses to confirm you own the domain.
  • The renewal job stopped running after a server update or migration.
  • A paid certificate wasn't renewed because the card on the account expired, or the reminder went to someone who left.

Two industry changes make this more likely, not less. Let's Encrypt stopped sending expiry reminder emails in 2025, so a failed renewal is no longer flagged for you. And certificate lifetimes are getting shorter for everyone: since March 2026 the maximum is 200 days, dropping in steps to 47 days by 2029. More renewals means more chances for one to fail.

How to check your expiry date

  • Fastest: enter your domain in our free SSL checker. It shows the expiry date, which addresses the certificate covers and whether browsers trust it.
  • In the browser: click the padlock (or the site settings icon) next to the address, then "Connection is secure" → "Certificate is valid". The "Expires on" date is shown.
  • From a terminal:
    echo | openssl s_client -connect yourdomain.com:443 -servername yourdomain.com 2>/dev/null | openssl x509 -noout -enddate
  • Don't forget subdomains. shop., booking. and mail. often have their own certificates and expire on their own schedule.

If it has already expired

  1. Log in to your hosting control panel (cPanel, Plesk or your host's dashboard) and look for "SSL/TLS" or "Let's Encrypt". There's usually a button to reissue or renew.
  2. If you use Cloudflare or another CDN, check its SSL settings too; there may be two certificates involved.
  3. For a paid certificate, renew it with the provider and install the new files (or ask your host to).
  4. Reload your site in a private window to confirm the warning is gone.

How to never miss it

Don't rely on remembering, and don't rely on renewal emails that no longer get sent. Use monitoring that checks the actual certificate your site serves. Daily Website Report checks your SSL certificate every day, along with uptime, security settings and SEO, and warns you weeks before expiry, so a failed renewal gets noticed while there's still time. It's free for one website.

While you're at it, check your domain's email security too. It's free and doesn't need an account.