Guide
"Not secure" or "SSL pending" on Squarespace, Shopify, Wix or GoDaddy
Your builder makes the padlock (the SSL certificate) for free, but only once your domain points at it. Usually it's a wait or one wrong record.
The SSL certificate is the small file behind the padlock: it proves the site is yours and seals what visitors type. On these four builders you never buy or install one yourself. Three things are true on all of them:
- It's free and automatic. Squarespace, Shopify and Wix don't accept a certificate bought somewhere else.
- It needs your domain pointing at the builder. A new or just-moved domain takes time: up to 48 hours on Squarespace, Shopify and Wix, and about 30 minutes on GoDaddy.
- "Not secure" with https in the address is something you added. Custom code, an embed or an app still loading a picture or script over plain http (called mixed content).
Which one have you got?
- "Not secure" and the address starts with http
- No working padlock yet, or visitors aren't sent to the https version. Follow your builder's steps below.
- "SSL pending", "processing" or "SSL Certificates Unavailable" in your builder
- The builder is still making the certificate, or can't, because your domain doesn't point at it yet. Your builder's steps below.
- Padlock with a warning, or "not fully secure"
- Mixed content. See Still "Not secure" with https.
- A full-page "Your connection is not private"
- The certificate is wrong for the address or has run out. See "Your connection is not private".
Not sure? Site health tells you whether your padlock works, the date the certificate runs out, whether http visitors are sent to https, and whether both the www and plain addresses work.
Squarespace: "SSL Certificates Unavailable" or "Not secure"
- New domain? Wait 48 hours. Squarespace says a new or just-connected domain can take that long, and an error in your domain settings meanwhile is normal.
- Check the status. Open your domains dashboard, click the domain, and check the SSL certificate status says Issued. If Squarespace can't make one, you'll see SSL Certificates Unavailable in the domain's overview panel.
- Set your site to Secure. Open the SSL panel (Squarespace's help page Understanding SSL certificates links straight to it). Under Security preference, check Secure and HSTS Secure, then click Save. Domains added before October 2016 start on Insecure, which lets people use the http version.
- Domain from Squarespace? Make sure its default records are still there. If it points to a website somewhere else, that host gives you the certificate, not Squarespace.
- Domain from another company? Check the records in that company's account match the ones Squarespace shows for your domain, and ask them whether they use CAA records (a setting that limits who may issue your certificate). A restriction stops Squarespace's certificate company issuing one.
- Forwarding your domain to another address? In the domains dashboard, click the domain, then Website, and edit the forward. If an SSL toggle shows and is off, turn it on and click Save.
- Check in a private window, 48 hours after any change. If it's fine there, clear your browser's cache.
Squarespace's support doesn't cover custom code. If you've added code blocks, code injection or an integration, any http address in them is yours to change (see mixed content).
Shopify: "SSL pending" or "SSL unavailable"
Look in Settings, Domains in your Shopify admin. When the domain says Connected and your store shows the padlock, it's done.
- SSL pending: wait 48 hours. Shopify says the certificate can take that long after you connect a domain bought elsewhere.
- Still pending, or SSL unavailable? At the company where your domain's records are kept, check:
- the A record is
23.227.38.65, - the AAAA record is
2620:0127:f00f:5::, - the www CNAME record is
shops.myshopify.com.(some companies want the dot on the end).
- the A record is
- Any CAA records? They must include
letsencrypt.org,pki.googandssl.com, or Shopify can't get a certificate. - DNSSEC switched on? Turn it off at your domain company. Shopify lists it as a cause of SSL unavailable.
- Only on one old phone? Shopify says Android 7.0 or lower, and browsers from before 2010, can't show the padlock. Update the device.
- Still stuck after 48 hours with every record right: contact Shopify Support.
Shopify counts any page with a picture, video or web font that isn't delivered over https as insecure. That usually comes from an edit to the theme's code or an old app.
Wix: SSL not working or "Not secure"
Wix turns https on for every site, and there's no switch to turn it off. Using your own domain needs a paid plan; the certificate itself is free.
- Domain bought from Wix, or connected with name servers? Go to Domains in your Wix account, click the Domain Actions icon next to the domain, and choose Manage DNS Records. Check the records in the A (Host) and CNAME (Aliases) sections; you can reset them to Wix's defaults.
- Connected by pointing? At the company where your domain is registered, the A record for
@must be185.230.63.107and the CNAME forwwwmust bepointing.wixdns.net. - Changed a record? Wait up to 48 hours. Wix issues the certificate only once the change has reached everyone, and the site may look insecure until then.
- Domain bought elsewhere? Ask that company to make sure DNSSEC isn't switched on for it. Wix says it can hold up the change.
- Pasted code into an HTML element? If it has
http://in it, change that tohttps://(or remove it), then publish again. Check every HTML element if you have more than one. - Only on one very old computer? Wix says Windows 7 or earlier, and very old Mac versions, may not trust its certificate. The site is fine; the computer needs updating.
Wix can't put a padlock on a domain that's connected to a website outside Wix.
GoDaddy Website Builder: "Not secure"
In your GoDaddy account the builder is called Websites + Marketing. Every plan comes with a free certificate, installed when you publish. GoDaddy says it can take up to 30 minutes after you connect your domain.
- Publish the site again. GoDaddy's fix when the certificate won't switch on is to republish, which starts the installation over. Go to your GoDaddy product page, expand Websites + Marketing, select Manage, then Edit Website, then Publish.
- Wait 30 minutes, then visit your site. The address should start with https and show the padlock.
- Domain in another GoDaddy account, or with another company? You may need to verify that you own it before the certificate is made.
- Still nothing? GoDaddy says conflicting CAA records can stop it. Ask whoever looks after your domain's records to check, then republish.
- Padlock there but still warned? Something you added, such as a custom HTML section or an embed, has an
http://address. Change it tohttps://.
If none of that works, contact GoDaddy: the builder's certificate is managed on their side.
Still "Not secure" with https (mixed content)
If the address starts with https but the browser still warns, the page loads at least one part over plain http. Browsers block some of those parts, so a picture can go missing or a button stop working. On a website builder it almost always comes from something added by hand:
- a code block, code injection or custom HTML section,
- an embed (a form, map, booking widget or video player) pasted in from another site,
- a picture linked from another website instead of uploaded,
- an edit to the theme's code, or an old app.
- Run Link Check on the page. It lists every picture, script, frame and stylesheet still loading over http, and marks each one Not secure.
- Change each address to start with https. If that version doesn't load, upload the picture or file to your builder and use that instead.
- Check the page again in a private window.
Send this to your web person
Not sure what to say? Copy this into an email, add your website's address, and send it.
Hi, Our website, [your website address], shows "Not secure" (or "SSL pending" in [Squarespace / Shopify / Wix / GoDaddy]). Our builder makes the certificate for free, so I think something is stopping it. Could you check, at the company where our domain's records are kept: 1. The A, AAAA and CNAME records match the ones our builder gives us, for both the www. and the plain address. 2. There's no CAA record blocking the builder's certificate company, and DNSSEC isn't getting in the way. 3. Nothing on our pages (code blocks, embeds, linked pictures) still loads from an http:// address. Please tell me what you found and what you changed, and I'll check for the padlock. Thanks
Check it's fixed, and stays fixed
- Site health shows the padlock working, when the certificate runs out and who issued it, and whether the www and plain addresses both work. Builders renew certificates by themselves, so the date moving on is a good sign.
- Site Watch checks every night and emails you only when something changes, such as the padlock breaking.
Facts checked on Oct 8, 2026.