An expired certificate does not make a site look slightly worse. It replaces the site with a full-page browser warning telling visitors the connection is not private. Automatic renewal handles this most of the time, and when it fails there is no notification, so the first signal is usually a customer asking whether you have been hacked.

What the visitor actually sees

Not a small icon change. A full-screen interstitial, in alarming language, that has to be actively dismissed before the site loads at all. The wording varies by browser and the substance is consistent: this connection is not private, attackers might be trying to steal your information.

For a business asking people to submit their name, address, and phone number, that is close to the worst possible first impression. Most visitors do not click through it. Many assume the business has been compromised rather than that a renewal failed, and some tell other people.

The failure is total rather than partial, which is what separates it from most website problems. A slow site loses some enquiries. An expired certificate loses nearly all of them for as long as it lasts.

Why automatic renewal fails

Modern certificates renew automatically and usually do. The failures are unglamorous and share a common feature: nothing tells you.

The pattern is the same one behind domain renewal failures: an automated process that has been working for years stops, and the only alert goes to an address nobody reads.

The failure that is harder to spot

Certificates are validated through a chain, and the intermediate links in that chain expire on their own schedule. A site can have a perfectly valid certificate and still fail for some visitors because an intermediate was not updated on the server.

This one is genuinely confusing because it is inconsistent. Newer browsers may load the site fine while older devices and some applications refuse it. The business tests it, sees no problem, and concludes the customer is mistaken. Checking the full chain rather than just the certificate is what separates a real test from a glance at the address bar.

What it costs in the first hour

Every enquiry that would have arrived, plus a proportion of the people who will not return. Search crawlers hitting the site during the outage record the failure. Any form, booking tool, or payment flow stops working. Links shared in advertising lead to a warning rather than a landing page, so paid traffic is being bought and discarded.

Because it is total, the arithmetic is simple. Take your daily enquiry count and treat it as lost for the duration. For most service businesses a day of that is a number worth several years of the monitoring that would have prevented it.

Monitoring it properly

The check worth doing today

Open your site and look at the certificate details, which every browser exposes in a few clicks. Note the expiry date. Then answer three questions: is renewal automatic, who is notified if it fails, and has anyone verified that the renewal process still runs since the last time the site or server changed.

Most businesses can answer the first and not the second or third. That gap is the whole problem, and it is the same gap covered in what the padlock actually means, where letting a certificate lapse is the failure with by far the largest consequences.


Frequently asked questions

What happens when an SSL certificate expires?

Browsers show a full-page warning saying the connection is not private, which must be dismissed before the site loads. Most visitors do not proceed, and many assume the business has been compromised.

Why did my automatic SSL renewal fail?

Usually because the validation challenge could not complete, often due to a firewall rule, a new redirect, or a security plugin blocking the path. DNS changes, a stopped scheduled task, and a suspended hosting account are the other common causes.

How do I know if my certificate is about to expire?

Every browser shows the expiry date in the certificate details. Relying on that means remembering to check, which is why an automated warning at thirty and seven days out is worth having.

Why does my site work for me but show a security error for others?

Frequently an intermediate certificate in the chain that was not updated on the server. Newer browsers may accept it while older devices and some applications refuse, which makes it appear that the customer is mistaken.

Do free SSL certificates expire faster?

They have shorter terms and are designed to renew automatically, which in practice makes them more reliable than annual certificates renewed by hand. The risk is not the certificate type, it is whether anyone is watching the renewal.

Does an expired certificate affect search rankings?

Crawlers hitting the site during the outage record the failure, and a prolonged outage can affect indexing. The larger and more immediate cost is that nearly every visitor turns away before reaching a page.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

When does your certificate expire?

We monitor certificates on every site we host, validate the full chain, and fix a failed renewal before your visitors ever see a warning.

Start a Conversation