Why does my website say “Not secure”?

Last updated October 5, 2026

Browsers like Chrome and Safari show “Not secure” next to the address when a page isn’t protected by HTTPS, the technology behind the padlock icon. If your security certificate has expired, some browsers show a full-page warning instead, and most visitors leave rather than click through.

The three common causes

  • No automatic redirect. Your site works with the padlock, but someone who types your address without “https://” lands on the unprotected version.
  • An expired certificate. Certificates last for a set time, often just a few months for free ones. They usually renew automatically, but renewal can stop working after a hosting or domain change.
  • Mixed content. The page is protected but loads an image, font or script over an unprotected address, so the browser drops the padlock or blocks the file.

How it’s usually fixed

  • Turn on “force HTTPS” or an HTTP-to-HTTPS redirect in your hosting control panel or website builder.
  • Ask your hosting company to renew or reissue the certificate, and to check that automatic renewal is on.
  • Find files still loaded with “http://” and change them to “https://”.

Most website builders handle all of this for you once your domain is connected correctly.

← All help articles