"Your connection is not private"
The website's security certificate, the thing behind the padlock, isn't valid: it has run out, it's for a different address, or it's set up wrongly. Your browser can't be sure it's talking to the real site, so it stops you.
What you'll see
- Chrome and Edge
- Your connection is not private, with a code such as NET::ERR_CERT_DATE_INVALID (run out), NET::ERR_CERT_COMMON_NAME_INVALID (for a different address) or NET::ERR_CERT_AUTHORITY_INVALID.
- Safari
- This Connection Is Not Private.
- Firefox
- Warning: Potential Security Risk Ahead.
If you're visiting a site
- Don't type passwords or card details on that site until it's fixed.
- Check your computer's date and time are right: a wrong clock makes every certificate look invalid.
- Try another network. Hotel, airport and café Wi-Fi sometimes cause this before you've logged in to the Wi-Fi page.
- If only one site shows it, it's that site's problem. Contact the business another way and tell them.
Stuck, and someone's helping you? Send them your details with My setup, or a screenshot and the error messages with PageKiwi for Chrome.
If it's your site
- Run Site health. It shows your certificate's end date and whether it matches your address.
- Ask your web host to renew or reissue the certificate. On most hosts it's free (Let's Encrypt or AutoSSL) and should renew itself, but renewals can fail quietly.
- If the warning mentions a different name, the certificate doesn't cover the address people use: often the www. version or the plain one. Ask your host to cover both.
- Sign up to Site Watch, so you get an email 14 days before it runs out next time.
Tools that help: Site health, Site Watch, What "Not secure" means.