Why does my website say "Not secure"?
The short answer: your browser shows "Not secure" when your website isn't using HTTPS properly. Usually that means there's no SSL/TLS certificate, the certificate has expired, or the page is loading some content over plain HTTP. It's almost always fixable in an hour or two, and often for free.
What "Not secure" actually means
When someone visits your site, their browser checks for a valid certificate. The certificate proves the site is really yours and lets the connection be encrypted, so nobody in between can read or change what's sent. That's the "S" in HTTPS.
If the certificate is missing, broken or doesn't match, browsers like Chrome, Edge, Safari and Firefox warn your visitors. Sometimes it's a small "Not secure" label in the address bar. Sometimes it's a full-page warning telling them to go back. Neither is a great first impression.
The usual causes
- No certificate at all. Older sites were often set up on plain HTTP and never updated.
- The certificate has expired. Certificates only last a set time. If renewal isn't automatic, or the automatic renewal broke, the site falls over on the expiry date.
- Mixed content. The page itself is on HTTPS, but an image, script or form on it still loads from an "http://" address. Browsers flag the whole page.
- The certificate is for the wrong name. A certificate for www.yourbusiness.co.uk doesn't automatically cover yourbusiness.co.uk without the "www", or the other way round. Visitors who type it differently get a warning.
- The site moved. A new host or a change to your domain settings can leave the old certificate behind.
How to check your certificate
You don't need any technical tools for a first look.
- Open your website in Chrome or Edge.
- Click the icon to the left of the web address (a padlock or settings-style icon on a secure site, or the words "Not secure").
- Look for "Connection is secure" or a message explaining the problem.
- Click through to the certificate details to see who it was issued to and the expiry date.
Try both versions of your address, with and without "www", and a few different pages, especially your contact form.
Why it matters
- Visitors leave. A warning makes people think the site has been hacked, even when it hasn't.
- Forms and logins aren't protected. Anything typed into a contact form, a login or a checkout could be read on the way. If you collect personal details, that's a data protection problem as well as an embarrassing one.
- Search ranking. Google has used HTTPS as a ranking signal for years. A site with warnings isn't doing your search results any favours.
- Email and trust links. If your site is linked from your email signature, every customer who clicks it sees the warning.
Free certificates and automatic renewal
Certificates don't have to cost anything. Let's Encrypt gives out free certificates, and most decent web hosts build it in. Let's Encrypt certificates currently last 90 days, and they're designed to renew automatically. The industry is moving towards even shorter lifetimes, so automatic renewal isn't optional any more.
Paid certificates still exist and some businesses prefer them, but for a typical small business website a free, automatically renewed certificate does the job.
What to ask your web host
If you're not sure where to start, send your web host (or whoever built the site) these questions:
- Is there a valid certificate on the site, and does it cover both the www and non-www addresses?
- Does it renew automatically, and who gets told if renewal fails?
- Does the site redirect everyone from http:// to https:// automatically?
- Are there any images, scripts or forms still loading over http:// (mixed content)?
If nobody can answer, or nobody knows who the host is, that's a sign it's worth getting someone to take ownership. While you're at it, check who controls your domain name too: see Who actually owns my domain name?
Common questions
Is my website hacked if it says "Not secure"?
Usually not. In most cases it's an expired or missing certificate. It's still worth fixing quickly, because visitors can't tell the difference.
Does a padlock mean a website is safe?
No. The padlock means the connection is encrypted and the certificate matches the address. It doesn't prove the business behind it is genuine. Scam sites can have padlocks too.
Do I need HTTPS if my site doesn't take payments?
Yes. Browsers warn on any page without it, and contact forms still collect names, email addresses and phone numbers. HTTPS is now the normal standard for every website.
Why did it break when nothing changed?
Because certificates expire on a fixed date. If automatic renewal stopped working, perhaps after a move to a new host or a change to your domain settings, the site will carry on as normal right up until the day the certificate runs out.
Want help with your website?
Tell us what you have now and what is bothering you. We will give you straight, plain-English advice, with no hard sell.