Website security warnings
Read the exact warning before trying to fix it
A browser warning can mean an HTTPS certificate problem, unsafe website content, mixed resources or a problem on the visitor’s device. Do not bypass a red phishing or malware warning. Identify the warning type first, then fix the underlying cause.
What does the browser warning mean?
Not secure
The page may be using ordinary HTTP, or the browser may not have established a valid encrypted HTTPS connection.
Your connection is not private
The certificate may be expired, issued for a different hostname, untrusted or missing part of its certificate chain.
Dangerous or deceptive site
The address may have been associated with phishing, malware, unwanted software or social engineering. Treat this as a separate security incident, not simply an SSL problem.
Mixed content
The main page uses HTTPS but loads an image, script, font or other resource over HTTP. The insecure resource must be updated or removed.
Diagnose the problem in the right order
Copy the exact warning and error code without including passwords or private account information.
Check the same public address on another current browser or device. Do not proceed through a dangerous-site warning.
Confirm the certificate covers the exact hostname, is in date and has a complete trusted chain.
Review DNS, redirects, mixed content and any malware or phishing report associated with the site.
Common fixes for website owners
| Finding | Likely fix | Do not do this |
|---|---|---|
| No HTTPS certificate | Issue and install a certificate for the live hostname, then redirect HTTP carefully | Do not assume a certificate for another hostname will work |
| Expired or mismatched certificate | Renew or replace it and check the full certificate chain | Do not tell visitors to click through the warning |
| Mixed content | Change embedded resources to trusted HTTPS addresses | Do not hide the warning with styling or scripts |
| Dangerous-site report | Investigate the site, remove harmful content, secure accounts and request review through the relevant search service | Do not treat it as only a certificate issue |
| One device only | Check its date, browser updates, network and security software | Do not change the public website before confirming the issue is reproducible |
For a UKC hosted website, use the SSL/TLS tools in Plesk and verify the active hostname. For a parked-domain website or another configuration, check the domain service in your account or ask support which SSL route applies.
Browser warning questions
Does every browser warning mean the site has no SSL?
No. Certificate errors are one category. Safe Browsing alerts, mixed content and local device problems have different causes and fixes.
Will adding SSL remove a malware warning?
No. HTTPS encrypts a connection but does not prove that the website content is harmless. Malware or phishing must be investigated and removed separately.
Why does the warning appear only on www or only without www?
The certificate or DNS may cover one hostname but not the other. Test both public addresses and make sure the certificate and redirect configuration include the intended names.
Is it safe to click Advanced and continue?
Usually you should not continue unless you fully understand and control the environment. Never bypass a warning on a login, payment or unfamiliar public website.
Need a secure hosted website?
Use hosting with managed HTTPS tools
UKC hosting provides Plesk SSL tools for hosted websites, with support available when the public configuration is unclear.