Skip to content
Menu

BlogGuides

Expired SSL certificate on your website: what actually happens

Rusty metal padlock hanging on a weathered industrial door
Add as a preferred source on Google

One click, and Google will show my articles more often in your results.

Anyone searching "expired SSL certificate" is usually already in the middle of the problem: they clicked on their own site and hit a screen they weren't expecting, or a customer flagged it to them. The question that matters isn't what the letters SSL stand for, it's what a visitor actually sees at that moment, and how serious it is.

What a visitor actually sees

When a site's certificate expires, visitors don't get a small warning tucked in a corner of the screen: they get a full page that covers everything else. Google Chrome's own official documentation confirms this, describing this kind of problem as a full-page error message and explicitly advising users to proceed with caution, or not use the site at all if it's flagged as dangerous. On Chrome the technical code is NET::ERR_CERT_DATE_INVALID, shown to the user as "your connection is not private"; Firefox and Edge show equivalent warnings in substance. In many cases it's still possible to force access by clicking a link hidden under "advanced", but that's a step most people, rightly wary, don't take.

It isn't, first and foremost, a Google ranking issue

A common belief is that an expired certificate makes a site disappear from Google's results. That isn't the case, or rather, it isn't the main reason to worry about it. Google has used HTTPS as a ranking signal since August 7, 2014, when it announced the change on its own official blog, describing it from the start as "a very lightweight signal, affecting fewer than 1% of global queries and carrying less weight than signals like content quality." That reference no longer appears in Google's current official guide to its ranking systems, but it's still cited among page experience factors in its documentation for site owners. So the problem with an expired certificate isn't, first of all, that Google penalizes the site: it's that whoever lands on it sees a warning that discourages them from staying, well before Google even comes into play.

Why it almost always happens for the same reason

A certificate doesn't expire because of an attack or a technical fault: it expires because it has an end date, and nobody renewed it in time. It happens even to companies with vast resources. On February 3, 2020, Microsoft Teams was unreachable worldwide for about three hours: the cause, announced at the time by the official Office 365 Status account, was "an authentication certificate has expired". It wasn't a website's public certificate, but an internal certificate that followed the same underlying logic: an expiry date nobody had marked on a calendar. The service returned for most users by late morning, US Eastern time, but the incident stayed memorable precisely because it wasn't some small site that tripped up: it was Microsoft.

What changes starting in 2026

As of March 15, 2026, the maximum validity of a public certificate dropped from 398 to 200 days: the CA/Browser Forum, the body that brings together the makers of the major browsers and the authorities that issue certificates, set this in a ballot approved on April 11, 2025. That means anyone who used to renew their certificate once a year now has to do it almost twice as often, and the schedule includes two further cuts: to 100 days from March 15, 2027, and to 47 days from March 15, 2029. For anyone handling renewal by hand, noting it on a calendar or relying on a reminder email, the risk of missing it grows in the same proportion.

The guarantee

Thirty days to change your mind.

In more than ten years I have never had a client unhappy with the work delivered. That is why I can afford to say this: you have 30 days from accepting the quote to stop, or until the site goes live if that comes first. Within that window I refund everything you have paid and we part ways, with no further claim and no argument. There are no conditions to meet and nothing to prove: you decide.

You get me, within one working day.

No switchboard, no support form. If you write or call and I do not answer within one working day, you do not pay that month.

I take the risk at the start. It is the only way I have to say “trust me” and have it mean something.

The difference that actually matters

Not every certificate renews the same way. Let's Encrypt, the world's most widely used free certificate authority, issues certificates valid for 90 days, and its own documentation recommends renewing them every 60, through a program installed on the server rather than a person who has to remember. That's the system most modern hosting now uses, including hosting built for people who don't want to deal with these details, as I've explained writing about website hosting. So the real risk isn't having an SSL certificate, which nearly every site has by now: it's having a renewal that depends on a person instead of an automatic mechanism. And with expiry dates now coming around more often, that margin for error keeps growing.

Where to start

If you manage your own site, the first thing to check isn't the certificate itself, but who renews it: if your hosting does it automatically, this problem rarely concerns you. If the certificate was instead bought separately, or installed by hand at some point in the past, it's worth checking when it expires before a customer discovers it for you. If you're not sure how your site is set up, get in touch and we'll check it together.

Frequently asked questions

What does a visitor actually see on a site with an expired certificate?

A full-page screen, not a small warning tucked in a corner. Google Chrome's own official documentation describes this kind of error as a full-page message, and explicitly advises proceeding with caution, or not using the site at all if it's flagged as dangerous. On Chrome the technical code is NET::ERR_CERT_DATE_INVALID, shown to the user as "your connection is not private"; Firefox and Edge show equivalent warnings. In many cases it's still possible to force access through a link hidden under "advanced", but most people, rightly wary, don't take that step.

Does an expired certificate make a site disappear from Google?

No, or at least that's not the main reason to worry about it. Google has used HTTPS as a ranking signal since August 7, 2014, but described it from the start, on its own official blog, as "a very lightweight signal, affecting fewer than 1% of global queries" and carrying less weight than signals like content quality. That reference no longer appears in Google's current official ranking systems guide, though it's still mentioned among page experience factors in its documentation for site owners. The real damage is different: visitors see a warning that discourages them from staying, well before Google even enters the picture.

Why do SSL certificates last less starting in 2026?

Because the CA/Browser Forum, the body that brings together the makers of the major browsers and the authorities that issue certificates, decided so in a ballot approved on April 11, 2025. As of March 15, 2026, the maximum validity of a public certificate dropped from 398 to 200 days. It will drop further: to 100 days from March 15, 2027, and to 47 days from March 15, 2029. Anyone renewing a certificate by hand now has to do it almost twice as often as before, and will have to do it even more often going forward.

How do you avoid a certificate expiring without anyone noticing?

By checking whether renewal is automatic. Let's Encrypt, the world's most widely used free certificate authority, issues certificates valid for 90 days, and its own documentation recommends renewing them every 60 through a program installed on the server, not by hand: that's the system most modern hosting now uses. If the certificate was instead bought separately or installed manually at some point, it's worth noting down when it expires, because with these shorter windows the margin for forgetting keeps shrinking.

Can an expired certificate happen even to large companies?

Yes. On February 3, 2020, Microsoft Teams was unreachable worldwide for about three hours: the cause, announced at the time by the official Office 365 Status account, was "an authentication certificate has expired". It wasn't a website's public certificate, but an internal certificate with the same underlying logic: an expiry date nobody had marked on a calendar. The service returned for most users by late morning, US Eastern time, that same day.

More articles

Want to be sure your site's certificate renews itself?

Tell me about your project