
The browser shows a warning, or the padlock is simply not there. There are five causes, and they are worth checking in this order: the first ones explain most cases and take seconds to rule out, and the last ones only make sense once the first ones are gone.
| Before anything else, close and reopen the browser, or open the site in a private window. Browsers cache certificates and pages, and more than once the padlock was already there and it was the computer showing the old version. Ten seconds, and it can save you the rest of this article. |
1. The domain does not point here yet
This is the first one to check, and the most common. A certificate can only be issued once the domain answers on the server the site lives on: validation works by querying the domain itself. If the domain still points somewhere else, or nowhere at all, there is nothing to issue.
How to check: look the domain up in WHOIS and read the nameservers. If they are not the ones from your account with us, that is your cause and the rest of this article does not apply yet. Sort the pointing out first and come back.
2. The certificate has not been issued yet
The free certificate that comes with hosting plans is issued automatically and renews itself, but it is not instant: the request is made, validated and installed, and that takes a while after the domain starts answering here.
How to check: in cPanel, find the SSL section. If the domain is listed with a valid certificate, it has been issued and your cause is elsewhere. If it shows no certificate, or a request in progress, give it time. If a long while passes and nothing is issued, tell us: almost always it means the domain still does not resolve here, or something is blocking validation.
| Bought a paid certificate and it never activated? A paid certificate does not install itself: it requires domain validation, usually an e-mail to an address on the domain itself, or a DNS record. Until that validation is done, the certificate waits and no padlock appears. |
3. Mixed content: the page is https, the parts are not
This is the confusing one, because the certificate is there and working. What happens is that the page is served over https but pulls in images, stylesheets or scripts from addresses that start with http. The browser cannot vouch for the whole page, so it drops the padlock or warns.
How to check: open the page, press F12 to open the browser developer tools and read the console. The messages name exactly which files came over http. Those are the ones to fix.
| On WordPress sites the cause is nearly always the site address stored in the settings still being http, or absolute addresses written into the content. Fixing the address in the settings clears most cases in one go. |
4. There is no redirect to https
The certificate is fine, but anyone typing the address without https still comes in through the old door, with no padlock. https exists here, it is just not compulsory.
How to check: type the address starting with https. If the padlock appears that way, the certificate is right and all that is missing is forcing https for everybody. That is done once and stays done.
5. The certificate belongs to another name
The browser says the connection is not private and that the name on the certificate does not match the address. It usually comes from one of three situations: you are opening the site through a temporary server address instead of the domain; you are using www and the certificate only covers the bare domain, or the other way round; or you have a subdomain that was not included when the certificate was issued.
How to check: click the browser warning and read which name the certificate was issued for. That name tells you immediately which of the three you are in.
The order, in one table
| Check | Sign that this is your cause |
| 1. The domain points here | The nameservers in WHOIS are not the ones from your account. |
| 2. The certificate was issued | The SSL section in cPanel shows no certificate for the domain. |
| 3. Mixed content | The padlock fails only on some pages, and the browser console names files loaded over http. |
| 4. Redirect | Typing https by hand shows the padlock; without it, nothing. |
| 5. Certificate for another name | The warning mentions a name mismatch, or you are using www and the certificate is not. |
|
Checked all five and still no padlock? Tell us the exact address you opened and we will look at what the browser is being handed. Open a support ticket |
|
SEE ALSO SSL certificates: what each one covers |
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $5.36/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











