SSL and the padlock

Why the padlock matters, when it appears, and what to do if you see "Not secure".

Every site we host gets HTTPS with a valid certificate, set up automatically. There is nothing to buy and nothing to configure.

What the padlock means

It means the connection between your visitor and your website is encrypted, so nothing in between can read or alter it.

It does not vouch for you as a business. It says the connection is private, nothing more. That is still important: browsers now mark sites without it as “Not secure” in the address bar, which is not what you want a prospective customer reading.

When it appears

Automatically, shortly after your domain starts pointing at us. The certificate cannot be issued until the domain resolves to our servers, so the sequence is always:

  1. Domain points at us
  2. DNS finishes propagating
  3. Certificate is issued
  4. Padlock appears

That middle step is why there can be a gap. Usually under an hour after the DNS resolves.

“Not secure” or a certificate warning

If you have just gone live or just changed your domain: wait an hour and try again. The certificate is probably still being issued.

If it has been longer than a few hours: get in touch. Something has not completed and we can see exactly what from our side.

If you see a warning about the wrong domain name: this usually means you are visiting a version of the address the certificate does not cover — for example www. when only the bare domain has resolved so far, or vice versa. It normally resolves itself as the rest of the DNS catches up.

Renewal

Certificates expire every 90 days and are renewed automatically well before that. You will never need to do anything, and there is no scenario where your site goes down because a certificate lapsed.

If you have added a CAA record to your domain, make sure it permits the authority we use — otherwise renewal will fail. Ask us before adding one.

Do I need to do anything about http versus https?

No. Anyone arriving at the http:// version is redirected automatically to https://. Both www and non-www work and settle on one canonical version, which is also better for search.

Beware of anyone selling you one

If you get an email offering to sell you an SSL certificate for your domain, it is either a scam or an unnecessary upsell. Yours is included, automatic, and already working.

The same goes for emails about “domain listing services” or urgent renewal notices from companies you have never heard of. If we registered your domain, we handle renewals and we will never ask you to pay a third party.