Where to start
Check the exact hostname, confirm its DNS and the certificate presented to visitors, then review renewal at the hosting or certificate provider. After the certificate is renewed and installed, test the same hostname again. A connection error alone does not prove expiry.
Open SSL checker1. Identify the hostname in the warning
Record the address shown by the browser. The root domain, www and a subdomain can use different configurations. If the page redirected before the warning appeared, the affected certificate may belong to the final destination.
Run SSL checker for that hostname. NetLuma attempts a verified HTTPS connection on port 443. When it succeeds and certificate metadata is available, it shows the issuer and validity dates in UTC.
If verification fails, read the message and check your hosting certificate panel. NetLuma may not return expiry details after a failed trusted connection. A timeout, hostname mismatch or incomplete chain can also prevent verification.
Check the hostname’s HTTPS certificate2. Find the provider serving that connection
Review the hostname’s DNS and compare it with the intended hosting configuration. A recently moved domain can still reach an old server through a cached answer or an address record that was left behind.
If a CDN or reverse proxy handles public HTTPS, review its certificate setup as well as the origin hosting setup. Renewing a certificate at one endpoint does not establish which certificate every visitor will receive. The relevant configuration depends on where the connection is terminated.
Inspect the hostname’s DNS3. Review renewal and installation status
For a certificate managed by your host, check the SSL or security area for the affected hostname, current status and any renewal or validation message. Confirm that the website is still hosted on the intended active service and that the domain points where the provider expects.
For a separately managed certificate, use the issuer’s renewal instructions and your server’s installation procedure. Renewal and installation are separate steps: obtaining a new certificate does not by itself update the certificate served by an existing endpoint.
4. If the website uses Hostinger managed SSL
Hostinger describes Lifetime SSL for its web, cloud and agency hosting as automatically installed and renewed while the website remains hosted there. For a PHP/HTML website, open its dashboard and Security → SSL to inspect the domain’s status.
If installation or renewal is failing, confirm the domain connection and follow the provider’s failure guidance. Contact Hostinger support with the affected hostname and displayed message when the managed renewal remains unresolved. An expiry warning does not automatically mean a paid certificate is required.
5. Verify what visitors receive after the repair
After the provider reports that the certificate is installed, run SSL checker again for the original affected hostname. Review trust first, followed by the new validity dates when available. Compare with a fresh browser session and another network if results differ.
Check each relevant hostname rather than assuming a repair to the root domain covers every subdomain. If different requests continue to show different certificates, ask the provider to review all configured addresses, proxies and serving endpoints.
| After the change | What to investigate |
|---|---|
| Verified; new validity dates visible | Confirm the same hostname opens normally in the browser. |
| Still reports the old certificate | Check whether DNS, a proxy or another endpoint reaches an older installation. |
| Trust fails for a different reason | Review the message for hostname, chain, validation or connection issues. |
On a small screen, scroll the table sideways to see both columns.
6. Make renewal easier to spot next time
Keep the hosting and certificate contact details current, review provider notifications and include the public hostnames in your maintenance checklist. With automated renewal, verify that the process remains successful after hosting, DNS or proxy changes.
NetLuma highlights a verified certificate with fewer than 14 complete days remaining. This is a point-in-time observation, not scheduled monitoring or a renewal service. A verified certificate protects the connection; it does not audit the application or establish that the website’s content is trustworthy.
Technical references
Provider documentation and technical explanations supporting this guide.