Fix an expired or expiring HTTPS certificate
Why a website certificate expires, how to renew it with cPanel, Let's Encrypt or Cloudflare, and how to stop it happening again.
By the Domain Health Hub team · Updated
- An HTTPS certificate is valid for a fixed period. Once it lapses, browsers show a full-page security warning.
- We fail the check under 7 days and warn under 21 days, on both the domain and www.
- Most certificates now renew automatically, so an expiring one usually means renewal has broken.
What this means
Every HTTPS certificate has an end date. We connect to the domain and to www once a day, read the certificate each one presents, and count the days left. Under 21 days is a warning; under 7 days, or already expired, is a failure.
Why it matters
When a certificate expires, browsers stop the visitor with a warning that the connection isn't private. Most people leave. Online shops stop taking orders, contact forms stop being used, and anything that calls the site from another system (payment callbacks, apps, monitoring) usually fails outright rather than showing a warning.
How to confirm it
Open the site in a browser and click the padlock to see the certificate's “valid to” date. Check both the bare domain and www, because they can carry different certificates.
How to fix it
cPanel hosting (AutoSSL)
In cPanel, open SSL/TLS Status, tick the domain and www, and choose Run AutoSSL. If it fails, the page says why: most often the domain no longer points at this server, or a redirect stops the validation request getting through.
Your own server with Let's Encrypt
Run your ACME client's renewal by hand (for Certbot, certbot renew) and read the error. Common causes are port 80 blocked by a firewall, a changed web server configuration, or the scheduled renewal task no longer running. Reload the web server afterwards so it picks up the new certificate.
Cloudflare (proxied)
With the orange cloud on, visitors see Cloudflare's edge certificate, which Cloudflare renews itself. If that one is expiring, check SSL/TLS > Edge Certificates for a stuck or failed renewal. With the grey cloud (DNS only), visitors see your server's own certificate, so renew it on the server.
If someone else manages the site, send them the date and the address affected. If the hosting account has lapsed, the certificate won't renew until it's paid.
Stopping it happening again
Use automated renewal wherever the host offers it, and make sure the domain and www both point at the server doing the renewal. Daily monitoring catches the rest: Domain Health Hub checks every client's certificates each day, alerts you by email or webhook, and lists upcoming expiry dates on the monthly report card.
Questions
My certificate renews automatically. Why are you warning me?
Automated certificates such as Let's Encrypt usually renew about 30 days before expiry. If one is still within 21 days of expiring, renewal has probably failed at least once, so it's worth checking now rather than on the day.
Do I need to buy a certificate?
Rarely. Free certificates from Let's Encrypt or your host's own scheme are trusted by every browser. Paid certificates mostly add support or warranty, not extra security for visitors.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.