Use automatic renewal, set an independent expiry reminder, and know how to check the date yourself. An expired certificate makes a site unreachable rather than merely insecure.

What visitors see

Not a small warning. A full-page interstitial saying the connection is not private, with the site behind a button most people will not press.

Which means an expired certificate does not merely degrade the site. It closes it entirely.

Search engines will also stop serving pages normally, and any form or transaction is unreachable.

For a business whose enquiries arrive through the site, that amounts to a complete outage caused by nothing more than a date passing.

Why it happens at bad times

Because certificates expire on a schedule set when they were issued, not at a convenient moment.

Free certificates typically run for ninety days, which means four renewals every year and therefore four separate opportunities to fail.

Paid ones run for a year, which means the failure is rarer and nobody remembers the process when it arrives.

Either way, the moment of expiry is entirely arbitrary: two in the morning, a Sunday, or partway through a holiday, which is precisely when nobody is watching for it.

The Christmas period is a particularly common time for this to bite, since a fortnight can pass before anybody notices.

The three ways it fails

The first is the most common with modern hosting, because automatic renewal works reliably until something changes and then fails silently.

A worked example

A business whose certificate expired on the twenty-seventh of December.

Automatic renewal had been failing for three cycles, sending notices to an address belonging to a former web designer.

Nobody in the business saw any of them.

The site showed a security warning for nine days over the holiday period before a customer phoned to ask whether they had been hacked.

The fix took twenty minutes once somebody looked at it.

The cost was nine days of a closed website during a period when people research work for the new year.

Making it not happen

Three layers, and the third is the one that actually saves you.

Automatic renewal, which most hosting provides and which handles it invisibly when it works.

Correct contact addresses on the hosting and registrar accounts, so notices reach somebody who will act.

And an independent reminder in your own calendar, a fortnight before expiry, which does not depend on any system working.

The third is the important one, because the first two both fail silently and the calendar entry does not.

Checking it yourself

Worth knowing how, since it takes seconds.

Click the padlock in the address bar and look at the certificate details, which show the expiry date.

Free online checkers do the same and will report the date without any clicking.

Doing that once now tells you when the next expiry falls, which is exactly the information needed in order to set the reminder.

Worth also checking the version with and without the www, since those can differ and a certificate covering only one leaves the other broken.

What the certificate does and does not prove

Worth being clear, since the padlock is widely misunderstood.

It proves the connection is encrypted and that the certificate was issued for that domain.

It does not prove the business is legitimate, that the site is safe, or that anybody verified who runs it, since a basic certificate is issued automatically to whoever controls the domain.

Which means a padlock on a fraudulent site is entirely normal and tells a visitor nothing about trustworthiness.

What matters for your own site is simply that it is present and current, since its absence is what visitors and browsers react to.

The counter-case

Where this needs less attention.

A site on managed hosting where certificates are handled entirely by the provider and have renewed without intervention for years, which is genuinely reliable for most modern platforms.

Even there, the calendar reminder costs nothing and catches the case where a provider changes something.

What does not reduce the need: paying for a certificate, which makes expiry less frequent rather than less consequential.

And a small site with little traffic, where the outage is smaller and the mechanism is identical.

Mixed content warnings

A related problem with a similar symptom and a different cause.

A page served securely that loads an image, script or font over an insecure connection produces a warning, or the item silently fails to load.

Which typically happens after a certificate is installed on an older site, where the addresses inside the pages were written before it existed.

The symptom is a padlock that shows a warning rather than a clean one, or an image that appears locally and not for visitors.

Fixing it means finding the insecure addresses and correcting them, which is a one-off job rather than a recurring one.

Over a holiday specifically

Worth a deliberate check before closing for any extended period.

Confirm the certificate does not expire during the break, and renew early if it does rather than relying on automation over a fortnight.

Check the domain renewal date at the same time, since that is the other date that closes a site entirely.

And check the card on file has not expired, which is the quiet cause of both.

Five minutes before closing, and it prevents the specific failure of a site being down for the exact two weeks during which nobody was looking at it.

The five-minute check

  1. Click the padlock and note the expiry date.
  2. Check the domain renewal date too.
  3. Put both in your calendar, a fortnight early.
  4. Confirm the notice address is one you read.
  5. Check the card on file.
  6. Renew early if either falls during a closure.

The fourth catches the most common underlying cause of all, since a notice sent faithfully to a former supplier every year is the same as no notice at all.

All six take about five minutes together, and they cover the two dates that can close a website entirely without anybody doing anything wrong.

The related renewal problem is covered in renewal notice to a dead address.


Frequently asked questions

What do visitors see?

A full-page warning saying the connection is not private, with the site behind a button most people will not press. It closes the site rather than degrading it.

Why does it happen at bad times?

Certificates expire on a schedule set when issued. Free ones run ninety days, so four renewals a year, and the moment is arbitrary: a Sunday, or a holiday.

Why does automatic renewal fail?

It works reliably until something changes, then fails silently, sending notices to an address that may belong to a former supplier.

What actually protects me?

An independent calendar reminder a fortnight before expiry. Automatic renewal and email notices both fail silently; a calendar entry does not.

How do I check the date?

Click the padlock in the address bar and look at the certificate details, or use a free online checker. Check with and without the www.

What should I do before a holiday?

Confirm the certificate does not expire during the break, check the domain renewal date, and check the card on file. Five minutes.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Closing for a fortnight?

Check the certificate and domain expiry dates first. Nine days of a security warning is a common way to start January.

Start a Conversation