What we checkCertificate & HTTPSTL-02
Your TLS certificate has expired
Every visitor now sees a full-page browser warning instead of your site.
- Check
- TL-02
- Included
- Free in every scan
What we check
The certificate your server presented has a notAfter date in the past.
Why it matters
This is not a degradation, it is an outage. Browsers refuse the connection and show an interstitial; most visitors leave.
It caps your grade at D for that reason alone.
The window between working and broken is a single second, and nothing degrades on the way. That is what makes it worth monitoring rather than checking: there is no early symptom to notice.
How to fix it
- 1
Renew the certificate now.
- 2
Then find out why the renewal did not happen — if it is automated, the automation has been failing silently for some time.
- 3
Add the domain to monitoring so the next one warns you 30 days out.
- 4
Check the certificate on
wwwas well as the apex — they are frequently issued and renewed separately, and one expiring alone is a common way this happens.
Common questions
- I use Let's Encrypt with auto-renewal.
- Then the renewal has been failing quietly, often for weeks. Check the timer or cron job actually ran, and look at its last output.
- How fast can I fix it?
- Minutes, with an ACME client. The renewal itself is quick; the reload of your web server is what people forget.
- Will visitors come back?
- Most will, but a browser warning is the one error users have been trained to treat as serious — which is exactly why it should not be routine.
See how your domain does on this check.
All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.