Seeing "Not secure" next to your own website's address is alarming, and your visitors notice it too. Browsers show the warning when the connection to the site isn't fully protected by HTTPS, and many people will leave rather than fill in a form or pay on a page with that label. The fix is almost always one of five things: no certificate, an expired certificate, a certificate for the wrong name, no redirect to HTTPS, or "mixed content" on an otherwise secure page.
What the warning actually means
HTTPS encrypts the connection between the visitor's browser and your server, using an SSL/TLS certificate that proves the server belongs to your domain. The browser shows a warning in two broad situations:
- The page was loaded over plain HTTP. Nothing is encrypted, so browsers label it "Not secure", and some show a stronger warning on pages with password or card fields.
- HTTPS was attempted but something is wrong. The certificate is invalid, expired or doesn't match the name, or the page loads some of its files over HTTP.
The first is a configuration gap; the second is a fault. Both are fixable. For the background on certificates, see SSL certificates explained.
Step 1: Check whether the site has a certificate at all
Type your address with https:// in front of it, for example https://yourbusiness.co.za.
- If the page loads with a padlock, you have a certificate: skip to step 4.
- If you get a certificate error, go to step 2.
- If it doesn't load at all over HTTPS, the site has no certificate for that name. Turn one on in your hosting panel.
On most modern hosting, free Let's Encrypt certificates are included. They're domain-validated and encrypt just as strongly as paid certificates; paid certificates add things like verified company details or wildcard cover.
Step 2: Read the certificate error
Click the warning or the icon next to the address to see the details. The common cases:
| Error | Cause | Fix |
|---|---|---|
| Certificate expired | Renewal failed or was never set up | Renew it; for Let's Encrypt, check that the domain still points at this server so automatic renewal can succeed |
| Name mismatch | The certificate covers example.co.za but you visited www.example.co.za (or the reverse) |
Issue a certificate that includes both names |
| Untrusted or self-signed | The server is showing a default certificate | Set the site up for this domain and issue a proper certificate |
| Incomplete chain | The intermediate certificate wasn't installed | Install the full chain your certificate provider supplied |
Why automatic renewal fails
Let's Encrypt certificates are valid for a short period and renew automatically. Renewal needs the certificate authority to reach your domain on the server that requests it. If you moved the domain's DNS to another server, put a proxy in front of the site or removed the www record, renewal can fail silently until the certificate expires. Checking your DNS first saves time; our DNS records guide shows what each record does.
Step 3: Cover every name visitors use
Visitors arrive on example.co.za, www.example.co.za and sometimes old domains you also own. Each name that serves the site needs to be on a certificate, or redirected before the browser expects a certificate for it. If you own several domains for one site, our guide to aliases and redirects for multiple domains explains how to handle them without duplicate content.
Step 4: Redirect HTTP to HTTPS
Having a certificate isn't enough if people still land on the HTTP version. Old links, printed material and bookmarks may all use http://. Set up a permanent (301) redirect so every HTTP request goes to the HTTPS address, and pick one canonical version, with or without www. www or non-www and HTTPS redirects walks through the options.
Once the redirect works, consider HSTS (the Strict-Transport-Security header), which tells browsers to use HTTPS for your domain automatically on future visits. Only turn it on once you're sure every subdomain you use works over HTTPS. See HTTP security headers for safe values.
Step 5: Fix mixed content
A page loaded over HTTPS that pulls in images, scripts, stylesheets or fonts over plain HTTP has mixed content. Browsers block insecure scripts outright and may show a warning or a broken padlock for the rest.
To find it:
- Open the page, press F12 to open the developer tools, and look at the Console tab. Mixed content warnings list the exact URLs.
- Search your site's content and theme files for
http://links to your own domain.
To fix it:
- Change the links to
https://, or to relative paths like/images/logo.png. - In WordPress, make sure the WordPress Address and Site Address settings use
https://, then update old links in your content with a search-and-replace tool, after taking a backup. - For third-party files that aren't available over HTTPS, replace them with a provider that offers HTTPS.
Step 6: Check forms and payment pages
If your site has a contact form, login or checkout, make sure the form's action address uses HTTPS too. A form on a secure page that submits to an HTTP address will trigger a warning in modern browsers. Payment pages from your payment provider are usually on their own secure domain; check that your links to them use https://.
A quick checklist
-
https://loads with a padlock on both the bare domain andwww - The certificate isn't due to expire soon, and renewal is automatic
- All HTTP requests redirect permanently to one HTTPS address
- No mixed content warnings in the browser console
- Forms submit to HTTPS addresses
- Sitemaps, canonical tags and internal links use the HTTPS address
The last point matters for search engines: once HTTPS works, make sure your sitemap and canonical tags list HTTPS URLs so search engines index the right version.
Frequently asked questions
Do I need a paid certificate to remove "Not secure"?
No. A free Let's Encrypt certificate removes the warning and encrypts the connection just as well. Paid certificates add verified company details, wildcard cover or a warranty.
Why does my site show a padlock on some pages but not others?
Usually mixed content on those pages: an image, script or embed loaded over HTTP. The browser console lists the files.
Will switching to HTTPS hurt my Google rankings?
Not if you redirect every HTTP address permanently to its HTTPS equivalent. HTTPS is a ranking signal, and search engines handle a correctly redirected move well.
My certificate renewed but browsers still show the old one. Why?
The web server may still be serving the old certificate from memory, or a proxy or CDN in front of the site has its own certificate. Restarting the site or checking the proxy usually resolves it.
On NewHost hosting, free Let's Encrypt certificates are issued and renewed for your domains automatically. Need business validation or a wildcard? See our SSL certificates, or browse web hosting plans that include free SSL.