← The KeepPaw Blog

Your connection is not private — what it means and how to fix it

A customer calls: "I tried to go to your website and Chrome says 'Your connection is not private.' Is it safe?"

Or worse — you try loading your own site and see that scary red warning page blocking the way. Your first thought: "Did someone hack my website?"

Deep breath. This warning almost always means your SSL certificate has a problem — expired, misconfigured, or missing entirely. It's not a hack, and it's fixable. Here's what's going on and what to do about it.

What "Your connection is not private" actually means

When someone visits your website, their browser (Chrome, Safari, Firefox, etc.) checks for an SSL certificate — a digital file that proves your site is legitimate and lets the connection be encrypted. Think of it like the lock on your front door.

If the browser can't verify that certificate — because it expired, doesn't match your domain name, or isn't installed correctly — it refuses to let visitors through. Chrome shows "Your connection is not private" (error code NET::ERR_CERT_DATE_INVALID or similar). Safari says "This Connection Is Not Private." Firefox says "Your connection is not secure." The exact words differ, but the problem is the same: your SSL certificate isn't working.

Here's the important part: this is blocking your real customers. They see a full-page warning, and most people close the tab immediately. You're losing business until it's fixed.

Why it happens to small-business websites

You didn't do anything wrong. SSL certificates expire — usually after 90 days (if auto-renewed through your host) or 1 year (if managed separately). When they expire, browsers stop trusting your site overnight.

Common causes:

  • Your SSL certificate expired. It had an expiration date, and that date passed. Auto-renew might have failed silently or wasn't set up.
  • Your website was just moved or launched. Someone built your site but didn't finish the SSL setup, or a recent change broke the configuration.
  • Your domain name changed. The SSL certificate is tied to a specific domain (like yourbusiness.com). If you switched from www.yourbusiness.com to yourbusiness.com (or vice versa) without updating SSL, browsers won't accept the mismatch.
  • Your hosting changed. You moved from one hosting company to another, and SSL didn't carry over automatically.
  • It only happens to some people. Browser caches can make the warning disappear for you even though customers still see it — or vice versa.

What to do right now

You don't need to understand how SSL works to fix this. Here's the checklist:

1. Confirm the problem is real

Open your website in a private/incognito browser window (this skips your cache) and see if you get the warning. If you do, it's real.

If only one customer reported it, ask them to send a screenshot. Sometimes the problem is on their end (old browser, clock set wrong, antivirus interfering). If multiple people see it or you see it yourself in incognito mode, it's your site.

2. Run a free SSL check

Go to KeepPaw's free website checker (or any SSL checker) and enter your website address. It'll tell you in plain English:

  • "SSL certificate expired" → Your certificate lapsed. Jump to step 3.
  • "SSL certificate invalid" or "name mismatch" → Your certificate doesn't match your domain or isn't installed correctly. Jump to step 3.
  • "No SSL certificate found" → Your site has no HTTPS setup at all. Jump to step 3.
  • "SSL is valid" → The certificate looks fine to the checker. The problem might be browser-specific or already fixed. Ask the person who reported it to try again in a private window.

3. Forward the results to whoever manages your website

If you didn't build the site yourself, email the check results to:

  • The person or company who built your website (web designer, developer, agency)
  • Your hosting company (Squarespace, GoDaddy, Bluehost, etc.) if they manage SSL for you
  • Your IT person, if you have one

Include:

  • The exact error message or a screenshot of the warning
  • The SSL check results from step 2
  • When it started happening (if you know)

That gives them everything they need to fix it without going back and forth.

If you built the site yourself on a platform like Squarespace, Wix, or Shopify, contact their support — they handle SSL for you and can usually renew or fix it in minutes.

4. If you manage your own SSL certificate

If you're technical or hired someone who set up SSL manually (not through Squarespace/Wix/etc.), here's the short version:

  • Expired certificate: Renew it through your SSL provider (Let's Encrypt, your domain registrar, your host). Most platforms can auto-renew — make sure that's turned on.
  • Misconfigured certificate: Check that the certificate matches your domain exactly, including www vs no-www. Reinstall if needed.
  • No certificate: Install one. Let's Encrypt offers free SSL certificates, and most hosts have a one-click setup.

This is more technical — if it's over your head, forward it to whoever does your hosting or web work.

How long does it take to fix?

If your host or web person is responsive:

  • Renewing an expired certificate: 5–30 minutes (fast on platforms like Squarespace, slower if manual)
  • Fixing a misconfigured certificate: 10–60 minutes (depends on the issue)
  • Installing a new certificate: 10–60 minutes

Once fixed, most people see the change immediately. Some might need to clear their browser cache or wait a few hours.

How to make sure this never happens again

Set up monitoring so you know before your customers do. KeepPaw watches your SSL certificate 24/7 and emails you warnings at 30, 14, 7, and 1 days before it expires — so you have plenty of time to renew before anyone sees a scary warning.

  • Uptime checks every minute mean you know within seconds if your site goes down
  • SSL expiry tracking emails you in plain English when your certificate is about to expire
  • Domain expiry alerts catch the other common "site suddenly vanished" problem

You don't need to remember to check. The schnauzer checks for you and barks when something needs attention.

Try KeepPaw free for 14 days. No credit card, just your website URL and email. If your SSL is about to expire, you'll get a clear warning with time to fix it before customers see that red screen.


The short version: "Your connection is not private" means your website's SSL certificate expired, is misconfigured, or is missing. It blocks real customers with a scary warning. Run a free SSL check, forward the results to whoever built your site or manages your hosting, and they'll know exactly what to fix. To catch it before customers do next time, set up monitoring that warns you before certificates expire.

Worried about your own site? Run a free 1-minute check — uptime, SSL, domain & more, in plain English.

Or start a free 14-day trial for 24/7 monitoring with instant alerts. 🐾

Keep reading: What Happens When Your SSL Certificate Expires (in Plain English)