Area: Website and certificates
HTTPS certificate
HTTPS certificate for your domain and www: issuer, validity, chain, cipher, key, signature and whether it still accepts TLS 1.0/1.1; HSTS preload if the homepage asks for it. It also checks the expiry and name of the certificates of subdomains already known from public certificate logs (at most 15, one TLS handshake each).
What it can report
Open each one to see what it means and how to fix it.
Expired certificate on a subdomain
What it means
What could happen
How an attacker would use it
How to fix it
- Decide whether tienda.example.com is still in use.Ask your team. It's often an old mail, portal or test address.
- If it's still used, renew its certificate in the service or hosting panel that serves it.
- If it isn't used, delete its record in your DNS settings so it stops existing.
- If it's used, turn on automatic renewal or add the date to a shared calendar.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Subdomain certificate expires soon
What it means
What could happen
How an attacker would use it
How to fix it
- Decide whether tienda.example.com is still in use.
- If it is, renew its certificate in the service or hosting panel that serves it, before the date.
- Turn on automatic renewal if your provider offers it, or add the date to a shared calendar.
- If it's not used, delete its record in your DNS settings.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Subdomain certificate doesn't match the name
What it means
What could happen
How an attacker would use it
How to fix it
- Decide whether vpn.example.com is still in use.Ask your team. It's often an old mail, portal or test address.
- If it is, get a certificate that includes this name and install it where the name is served.
- If it isn't, delete its record in your DNS settings so it stops pointing anywhere.
- If you don't recognize the server it points to, tell your IT person.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
No HTTPS available
What it means
What could happen
How an attacker would use it
How to fix it
- Check that example.com points to the right server in your DNS settings.A name that points nowhere also produces this error.
- Get a certificate for that name.Let's Encrypt certificates are free, and most hosts and website builders have a free “HTTPS” or “SSL” option in their dashboard.
- Turn on HTTPS in your hosting plan or server and install the certificate.
- Redirect the unencrypted address (http://) to the secure one (https://).
- Open example.com in a browser and check that the padlock shows.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Expired certificate
What it means
What could happen
How an attacker would use it
How to fix it
- Renew the certificate today in your hosting panel or with whoever issued it.Most hosts renew with one click. If you use a free certificate, check why its automatic renewal stopped.
- Install the renewed certificate on the server, including the intermediate certificates the issuer gives you.
- Turn on automatic renewal, or put the expiry date in a shared calendar with a reminder a month before.
- Open example.com in a browser and check that the warning is gone.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Certificate expires soon
What it means
What could happen
How an attacker would use it
How to fix it
- Renew the certificate now in your hosting panel or with whoever issued it.
- Find out why automatic renewal didn't work.Common causes: a changed DNS record, a redirect that blocks the renewal check, or an expired payment method.
- Install the renewed certificate on the server and check the new expiry date in the browser's padlock details.
- Put the next expiry date in a shared calendar, with a reminder a month before.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Certificate doesn't match the name
What it means
What could happen
How an attacker would use it
How to fix it
- Check which names the current certificate covers: open example.com in a browser and look at the certificate's details.The details of this finding also list the names it was issued for.
- Get a certificate that includes example.com, ideally together with the other names you use (for example, with and without “www”).
- Install it on the server or hosting plan that answers to this name.
- Check that the name in your DNS points to the server you intend. If you don't recognize that server, tell your IT person.
- Open example.com again and check that the warning is gone.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Incomplete certificate chain
What it means
What could happen
How an attacker would use it
How to fix it
- Download the “full chain” (or “bundle”) file from whoever issued your certificate.
- Install that file on the server instead of the single certificate.Hosting panels usually have a field for the certificate and another for the “chain” or “CA bundle”.
- Restart or reload the web server, or ask your host to do it.
- Open example.com on a phone and on a computer to check that neither shows a warning.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Only old TLS versions
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your host or IT person whether the server supports TLS 1.2 and 1.3.Any recent server does. If yours doesn't, the server's software is outdated.
- Turn on TLS 1.2 and 1.3 in the server's or hosting plan's settings.
- Turn off TLS 1.0 and 1.1.
- If the server can't be configured, update it or move to a hosting plan that is maintained.
- Open the site in a browser and check that it loads normally.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Still accepts old TLS versions
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your host or IT person to turn off TLS 1.0 and 1.1, leaving only 1.2 and 1.3.
- In your own server or hosting plan, look for the “minimum TLS version” setting and set it to 1.2.
- Check afterwards that the site works from a recent phone and a computer.
- If an old device or system you own stops working, plan to update it instead of reopening the old versions.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Certificate signed with SHA-1
What it means
What could happen
How an attacker would use it
How to fix it
- Ask whoever issued the certificate, or your host, to reissue it.Don't just “renew” the old one: ask for a new one with a modern signature (SHA-256 or stronger).
- Install the new certificate on the server in place of the old one.
- Check that the new certificate doesn't need an intermediate certificate that is also old.
- Open example.com in a browser and check the padlock.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Certificate key too short
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your host or whoever issued the certificate to create a new certificate with a new key of 2048 bits or more.ECDSA keys are also fine, if your host offers them.
- Make sure it's a new key, not just a renewal with the old one.Many panels have a “regenerate key” or “new private key” option.
- Install the new certificate on the server in place of the old one.
- Open example.com in a browser and check the padlock.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Weak encryption negotiated
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your host or IT person to turn on TLS 1.3 on the server.
- In the server's or hosting plan's settings, remove the weak ciphers and keep the modern ones.Modern ones are those that offer forward secrecy (ECDHE) and AES-GCM or ChaCha20.
- If your host doesn't offer these settings, ask whether a newer plan or server includes them.
- Check that the site works from a recent phone and a computer.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Asks for HSTS preload but isn't listed
What it means
What could happen
How to fix it
- Check that all your subdomains work over HTTPS, including old ones.The list applies to every subdomain, so one without HTTPS would stop working for visitors.
- Check the requirements on the HSTS preload site (a long “max-age”, “includeSubDomains” and “preload”).
- Submit the domain at hstspreload.org once the requirements are met.
- Alternatively, remove “preload” from your header if you don't want to join.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.