Your website says “Not secure” and you don't know what to change. Check HTTPS, your certificate and domain settings before paying for a fix you don't need.
You open your new website and see “Not secure” beside the address. The page looks fine, but that warning is what a customer sees before deciding whether to send you a message.
Start with the warning itself. A missing secure connection, an expired certificate and a red unsafe-site screen are different problems.
Why does my website say “Not secure”?
Your browser is warning you about the connection or the site's safety.
Your website can say “Not secure” because it opens over HTTP, which doesn't encrypt the connection. A certificate error means the browser can't verify the HTTPS connection. A red dangerous-site warning needs a separate safety check.
Match the wording to the next step.
| Warning | What it means | First action |
|---|---|---|
| Not secure on an HTTP address | The connection isn't encrypted | Try the HTTPS address |
| Your connection is not private | The secure connection can't be verified | Save the error code |
| Red dangerous-site screen | The site has been flagged as unsafe | Check Search Console's Security Issues |
Chrome explains these connection warnings. Don't enter passwords or customer information while a warning is showing.
A red screen doesn't mean you should buy a certificate. Follow the reported issue in Google's Security Issues report, fix it and use its review process.
What should you check first?
Test the exact address your customers use.
Copy the full address, take a screenshot and note any error code. Then open your site in a private browser window, which shows you its current state rather than an old tab.
Try these four versions, replacing example.com with your domain:
http://example.comhttps://example.comhttp://www.example.comhttps://www.example.com
They should lead to your chosen secure address without a warning. Write down which version fails. One can work while another doesn't.
If HTTPS works but HTTP still shows “Not secure”, the likely next job is sending visitors from the old address to the secure one. If HTTPS itself fails, check the certificate first.
You'll need your hosting account and the account managing your domain records. Those records (DNS) tell browsers where to find your website, and they're sometimes managed somewhere other than where you bought the domain.
How do you fix HTTPS on your website?
Most hosted sites let you manage HTTPS from the domain settings.
1) Check the certificate
Look for “Domains”, “HTTPS” or “SSL” in your hosting dashboard. A certificate is the digital proof a browser uses to check the site's identity.
Confirm that your exact domain is connected and its certificate is active. If you can view the certificate, check its expiry date and the domain names it covers.
Many hosts provide and renew certificates automatically. Let's Encrypt also provides free certificates, so buying one isn't the first step.
Renewing the domain you bought doesn't renew its certificate. If your host reports a failed renewal, ask support to identify the cause.
2) Check your custom domain
The preview address from an AI builder has its own setup. It can be secure while your custom domain is still waiting for verification.
Use your platform's current instructions:
Copy the records shown for your own project. Don't replace your entire domain setup with values from an unrelated tutorial.
If the dashboard says verification or certificate setup is pending, allow the stated setup time. If it reports an error or stays stuck, use its retry option or contact support with the exact message.
3) Replace insecure files
An HTTPS page can still try to load an image, script or other file over HTTP. This is called mixed content.
Ask your developer to check the browser's error messages for HTTP files and replace them with secure addresses. Some browsers block those files, so this can also explain a missing image or broken feature.
4) Send old addresses to HTTPS
Once the secure version works, use your host's redirect settings for the other addresses. A redirect automatically takes a visitor to the preferred version.
Keep the page path intact: someone opening a service page should reach that service page, not the homepage. Update old links in your navigation and marketing profiles too.
What if the warning appears only on one device?
The device or network may be part of the problem.
Check the device's date and time, then try an updated browser and another network. A wrong clock can make a valid certificate appear expired; Chrome's connection-error guidance explains the checks.
Don't dismiss a customer's report because your laptop works. Ask for the full address, warning, device and time. Compare that exact address yourself.
If the warning keeps returning, we can find the faulty part of the setup and fix it. We repair custom-coded sites, with the price depending on what's wrong. If the site runs on Framer or Webflow, we'd discuss a rebuild rather than a repair. An intro call costs nothing and commits you to nothing; you can also email hi@aruno.studio or message us on WhatsApp or Telegram at @mihaipostelnicu.
For problems visitors can see, such as design, speed, copy and SEO, our website audit is the quicker route. HTTPS working doesn't prove the rest of the website works: an enquiry form, for example, can fail without anyone noticing.
Which fixes should you avoid?
A quick workaround can leave the real problem in place.
| Shortcut | Why it fails | Better action |
|---|---|---|
| Buy a certificate immediately | Your host may already supply one | Check the existing setup |
| Delete all domain records | Your business email may break | Change only the incorrect record |
| Disable browser warnings | Customers still see the problem | Repair the connection |
| Rebuild the page design | Domain settings may be the cause | Diagnose the warning first |
After a change, repeat all four address tests and open a page beyond the homepage.
Frequently asked questions
Does “Not secure” mean my website was hacked? Not necessarily. An HTTP connection or certificate problem can cause a warning without a hack. A red dangerous-site screen needs its own investigation.
How much does fixing HTTPS cost? The certificate may already be included in your hosting. You may need to pay someone to repair the configuration, but ask what failed before buying anything.
How long does the fix take? A wrong setting can be quick to correct. Domain verification and certificate setup may need time, so follow your host's stated process.
Can I fix it in Lovable or Bolt? Often, the relevant settings are in the domain dashboard. Give the builder or support team the exact address and warning instead of asking it to redesign the website.
Will HTTPS make my website rank on Google? HTTPS alone doesn't guarantee visibility or rankings. If your secure site still isn't appearing, use these Google visibility checks.
Your customers should reach the secure page without thinking about the connection. Test the address they actually open.
