Skip to content

What we checkCertificate & HTTPSTL-02

Your TLS certificate has expired

Every visitor now sees a full-page browser warning instead of your site.

Check
TL-02
Included
Free in every scan

What we check

The certificate your server presented has a notAfter date in the past.

Why it matters

This is not a degradation, it is an outage. Browsers refuse the connection and show an interstitial; most visitors leave.

It caps your grade at D for that reason alone.

The window between working and broken is a single second, and nothing degrades on the way. That is what makes it worth monitoring rather than checking: there is no early symptom to notice.

How to fix it

  1. 1

    Renew the certificate now.

  2. 2

    Then find out why the renewal did not happen — if it is automated, the automation has been failing silently for some time.

  3. 3

    Add the domain to monitoring so the next one warns you 30 days out.

  4. 4

    Check the certificate on www as well as the apex — they are frequently issued and renewed separately, and one expiring alone is a common way this happens.

Common questions

I use Let's Encrypt with auto-renewal.
Then the renewal has been failing quietly, often for weeks. Check the timer or cron job actually ran, and look at its last output.
How fast can I fix it?
Minutes, with an ACME client. The renewal itself is quick; the reload of your web server is what people forget.
Will visitors come back?
Most will, but a browser warning is the one error users have been trained to treat as serious — which is exactly why it should not be routine.

See how your domain does on this check.

All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.