My website says "Not secure". How do I fix it?

Also searched as: My website says not secure how to fix · My website is not secure how to fix · My website showing not secure in Chrome · SSL certificate not working · SSL certificate not working on subdomain · SSL certificate error how to fix

Updated 3 October 2026

Short answer

Your browser is saying it can't confirm a private, encrypted connection to your site. Either the site has no HTTPS certificate, the certificate has expired, it doesn't cover the exact address being visited (with or without www, or a subdomain), or the page loads something over plain http. Certificates are available free, and most hosts install and renew them automatically, so this is usually fixed in your hosting dashboard.

What's the problem

Chrome shows "Not secure" next to your address, or a full-page warning before anyone sees your site. Visitors leave, and anyone asked to log in or pay sees a reason not to.

Why it happens

  • No HTTPS at all. The site is served over plain http. Browsers label that "Not secure", because anything sent to the site could be read or changed on the way.
  • The certificate expired. The most common free certificates last 90 days and are meant to renew automatically. If the renewal breaks, say because the domain moved or a server changed, the certificate quietly runs out.
  • It doesn't cover this address. A certificate for yoursite.com doesn't automatically cover www.yoursite.com or shop.yoursite.com. Each address needs to be included.
  • Mixed content. The page is HTTPS, but it loads a script, form or image over http. Browsers block or upgrade those requests, and some show the page as not fully secure.

How to fix it

  1. Click the icon next to the address in the browser. It says whether there's no certificate, an expired one, or one issued for a different name.
  2. In your hosting dashboard, turn on HTTPS for every address you use, with and without www. Most hosts issue free certificates and renew them for you.
  3. If you manage your own server, check the renewal job is running, and renew now if the certificate has lapsed.
  4. Redirect http to https, so nobody lands on the insecure version.
  5. Fix mixed content. Open the browser console and change any http:// links to scripts, images, forms or fonts to https://.

When to call Preventionlabs

A lone expired certificate is a do-it-yourself fix, and the steps above cover it. Call us when "Not secure" is just the visible part of a bigger problem: a site nobody can update, logins and user data you're not confident about, a server nobody maintains. HTTPS is one item on the MVP-level protection checklist in every resurrection, alongside logins, access control, data exposure and the rest.

Submit your project for a free assessment

Free assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.

Sources

  1. Google Chrome Help: Check if a site's connection is securebrowser docsTo resolve this issue, the site owner must secure the site and your data with HTTPS.
  2. Let's Encrypt: About Let's Encryptcertificate authorityWe give people the digital certificates they need in order to enable HTTPS (SSL/TLS) for websites, for free, in the most user-friendly way we can.
  3. Let's Encrypt: FAQcertificate authorityOur default certificates are valid for 90 days.
  4. MDN Web Docs: Mixed contentweb referenceBrowsers mitigate the risks of mixed content by auto-upgrading image, video, and audio mixed content requests from HTTP to HTTPS, and block insecure requests for all other resource types.
← All of Live but broken