Get it fixed
SSL Not Working? Certificate, HTTPS and Mixed Content Fix
Certificates, redirects, mixed content, security headers and HSTS fixed without breaking the site: $59.
Short answer: “Not secure” warnings, ERR_CERT_DATE_INVALID, redirect loops after enabling HTTPS, AutoSSL or Let’s Encrypt failing to renew, or a padlock with a warning triangle usually come from an expired or incomplete certificate, a validation (DCV) failure, a CAA record, a CDN in the wrong SSL mode, or mixed content. Our Website security and SSL fix fixes the certificate, redirects and mixed content and sets security headers and HSTS without breaking the site, for a fixed $59.
Fix my SSL: $59 You see the price and scope before anything starts. Nothing is charged without your OK.
Signs this is your problem
- Browsers show “Your connection is not private”, “Not secure” or a certificate name mismatch.
- AutoSSL or Let’s Encrypt renewals fail with DCV or CAA errors, or the certificate is about to expire.
- The site loops between HTTP and HTTPS (“too many redirects”), often after turning on Cloudflare.
- The padlock is missing on some pages because images or scripts still load over HTTP.
- Mail clients warn about the certificate on IMAP or SMTP, because the mail service uses a different certificate from the website.
- Our SSL certificate checker or security headers checker reports problems.
What we do
- Check the certificate, its chain, the names it covers and the TLS versions from outside, the way browsers see it.
- Fix issuance: DCV failures (blocked
.well-knownpaths, redirects, proxied DNS), CAA records that forbid your certificate authority, and stale certificates installed on the panel. - Fix redirects so every address goes to one HTTPS version in a single hop, and set the correct CDN SSL mode (for Cloudflare, Full (strict) instead of Flexible).
- Find and fix mixed content in the theme, database and hard-coded URLs.
- Add security headers and HSTS carefully: HSTS starts with a short max-age and only goes long once every subdomain works over HTTPS.
- Rerun the website health test before and after, and send a short written report.
What is included and what is not
- Included: one website (its www and non-www names, plus the mail and panel hostnames on the same server), certificate, redirects, mixed content, security headers and HSTS.
- Not included: buying a paid certificate (free Let’s Encrypt or AutoSSL certificates are used unless you supply one), a Content Security Policy that needs development work on the site, or application bugs unrelated to HTTPS.
Why certificates fail more often now
Public certificate lifetimes are getting shorter: the CA/Browser Forum has agreed to cut maximum validity from 398 days to 200 days in 2026, 100 days in 2027 and 47 days in 2029. Every renewal is another chance for DCV to fail, so a setup that renewed once a year without anyone noticing now has to work every few weeks. See the 47-day certificate lifetime and 200-day certificates and DCV reuse for details.
What we need from you
- The website address and where DNS is hosted (for example Cloudflare, your registrar or the server).
- A temporary panel login or SSH key for the server. Never send passwords by email or in the order form.
- Access to your CDN or DNS provider, or a contact who can apply the changes we send.
Prefer to do it yourself?
The guides AutoSSL failed: DCV, CAA and CDN problems and cPanel hostname SSL cover the common causes, and the HTTP redirect checker and CAA and TLSA checker show what is wrong from outside.
Fix my SSL: $59 You see the price and scope before anything starts. Nothing is charged without your OK.
Frequently asked questions
Do I need to buy an SSL certificate?
Usually not. Free certificates from Let’s Encrypt, or the AutoSSL certificates included with cPanel, are trusted by every current browser. We only install a paid certificate if you already have one or your organisation requires it.
Will HSTS break my site?
It can if it is turned on before everything works over HTTPS, because browsers then refuse plain HTTP. That is why we start with a short max-age and only extend it, or add includeSubDomains, after checking every subdomain.
My site uses Cloudflare. Is that covered?
Yes. Most Cloudflare loops come from the Flexible SSL mode. We install a valid certificate on the server and switch to Full (strict), so traffic is encrypted all the way.
What about the mail server certificate?
Mail clients check the certificate on the IMAP, POP3 and SMTP hostnames. If they share the server with the website, we fix them in the same job.
How long does it take?
Usually one to two business days. Certificate issuance itself takes minutes once validation works.