Tools › Guides

Why Your Website Says "Not Secure"

Chrome shows "Not secure" for several different reasons, and the fix is different for each. Here is how to tell which one you are looking at.

It usually is not your certificate

The most common cause is the simplest: the page was served over plain http:// rather than https://. No certificate is involved at all — the browser is telling you the connection was never encrypted in the first place.

If typing https:// in front of your address loads the site fine, your certificate is working and the problem is that visitors are not being sent there. That is a redirect you are missing, not a certificate you need to buy.

The four causes, in the order worth checking

1. No redirect to HTTPS. The site works on https but visitors land on http. Fix it with a permanent redirect at the web server or host, then add HSTS so browsers stop trying http at all.

2. The certificate expired. Certificates last 90 days to a year and renewal is meant to be automatic. When automation breaks it usually fails silently, and the first thing anybody notices is the warning.

3. The certificate does not cover the hostname. A certificate issued for example.com does not cover www.example.com unless it lists both. This is why a site can be fine at one address and broken at the other.

4. Mixed content. The page itself is served over https but pulls an image, script or stylesheet over http. The padlock breaks even though your certificate is perfect. Chrome's console names the offending URL.

How to tell which one you have

Check the certificate itself before changing anything. If it is valid, unexpired and covers the hostname, then your problem is a redirect or mixed content, and no amount of reissuing certificates will help.

That is the whole point of checking first: three of these four causes are not fixed by touching the certificate, and replacing a working certificate costs you an afternoon and changes nothing.

Check your certificate → Expiry, chain, hostname match and weak signatures — free, no signup

Common questions

Does "Not secure" mean my site has been hacked?

No. It means the connection between the visitor and your server is not encrypted, or the certificate proving your identity has a problem. It says nothing about whether your site has been compromised.

Will a "Not secure" warning hurt my search ranking?

HTTPS is a lightweight ranking signal, so the direct effect is small. The larger cost is behavioural: visitors who see a browser warning leave, and forms on an insecure page are flagged by Chrome as the user types.

Do I need to pay for an SSL certificate?

No. Let's Encrypt issues free certificates trusted by every major browser, and most hosts set them up automatically. Paid certificates differ in warranty and validation level, not in the encryption itself.

More guides