Do not enter passwords or payment details through a warning
A certificate warning can indicate simple expiry or a hostname mismatch, but it can also mean the browser cannot verify the server. Record the message and correct the route or certificate first.
Identify the warning
Test the exact public address
- Check the device date and time, then open the site in a current browser.
- Test both
https://domainandhttps://www.domainif both are used publicly. - Open the browser's certificate information and record the expiry date and names covered.
- Check where the domain's A/AAAA records currently send website traffic.
- Confirm whether the site is UKC parked, UKC hosted or hosted by another provider.
Common messages
The warning describes the required correction
- Expired certificate
- Renew or reissue it at the current web host, then verify the new expiry date.
- Name mismatch
- The certificate does not cover the exact hostname. Add that name or redirect only after it has valid HTTPS.
- Untrusted issuer or incomplete chain
- Install the correct certificate chain at the web server. Self-signed certificates are not trusted publicly.
- HTTPS unavailable
- The host may not have a certificate or may not be serving port 443 for that domain.
- Mixed content
- The page is secure but loads some images, scripts or styles over HTTP. Update those resource URLs.
- Wrong website or certificate
- DNS may point to the wrong server, or the server's virtual-host configuration may not contain the domain.
UKC hosting
Issue or renew Let's Encrypt in Plesk
Confirm the domain and every requested hostname point to the assigned UKC hosting server. In Plesk, open SSL/TLS Certificates or Let's Encrypt, request the required names, then assign the certificate to the website. Validation must be able to reach the domain; external proxy or restrictive DNS settings can prevent issuance.
Enable an HTTP-to-HTTPS redirect only after the HTTPS address works correctly.
UKC parking
Domain Security applies only while website traffic reaches UKC parking
Open the domain's Domain Security page in Client Area to review its status. If the A record points elsewhere, that external website must provide its own certificate; buying or renewing UKC parked-domain security will not secure an unrelated server route.
External website
Ask the provider receiving traffic to install the certificate
UKC can manage the domain while Wix, Shopify, Lovable, Cloudflare or another provider hosts the website. Follow that provider's certificate process and keep its required DNS records. Do not reset working external DNS merely because the certificate is managed elsewhere.
Check every public hostname after the fix
The browser should show no warning for the root domain, www and any public secure subdomain. Confirm the certificate covers the exact name, presents a trusted chain and has a future expiry date.
Security warning remains?
Send the exact HTTPS URL, warning text or code, certificate expiry and covered names, current web host, DNS result, time tested and whether root and www behave differently. Never send a private key.
Ask the Hosting team