Fix a certificate name mismatch
Why a site shows a certificate for the wrong name, how to cover both the domain and www, and what to do when only one of them answers.
By the Domain Health Hub team · Updated
- A certificate only covers the names listed in it. Visit any other name and browsers show a warning.
- The usual cause is a certificate for example.com but not www.example.com, or the reverse.
- The fix is a certificate covering both, or a redirect from one name to the other once both have HTTPS.
What this means
A certificate lists the names it's valid for. When we connected to the domain or to www, the server presented a certificate that doesn't include that name. Often it's the hosting company's own default certificate, which means the server doesn't know about the site at all on that name.
Why it matters
Browsers treat a wrong name exactly like an expired certificate: a full-page warning that most visitors won't click past. People type www and leave it off in roughly equal measure, and links from other sites use both, so a mismatch on either one loses visitors.
How to confirm it
Visit https://example.com and https://www.example.com. On the one with a warning, view the certificate and look at the names it lists (the “Subject Alternative Name” field).
How to fix it
cPanel hosting (AutoSSL)
Make sure both names are set up on the account (www is usually added automatically), then run AutoSSL from SSL/TLS Status. If www is missing from the list, check its DNS record points at the same server.
Your own server with Let's Encrypt
Issue one certificate for both names, for example certbot --nginx -d example.com -d www.example.com, and check the web server's configuration answers for both.
Cloudflare
Cloudflare's free edge certificate covers the domain and one level of subdomains, so a proxied www is covered. If www is set to DNS only, the server behind it needs its own certificate for www.
Once both names have a valid certificate, redirect one to the other if you prefer.
When only one name answers
We also note when only one of the domain and www accepts HTTPS connections at all. If nobody uses the other name, that's harmless. If people do, add a DNS record for it pointing at the site, give it a certificate and redirect it. Domain Health Hub re-checks both names every day and tells you when either one changes.
Questions
Can I just redirect www to the bare domain?
Yes, but the redirect itself happens after the HTTPS connection is made. If www has no valid certificate, visitors still see the warning before the redirect. Both names need a certificate.
Does a wildcard certificate cover the bare domain?
No. A certificate for *.example.com covers www.example.com and other single-level names, but not example.com itself. Most wildcard certificates list both for that reason.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.