Why does Chrome say "Not Secure"?
Chrome shows "Not Secure" when your site loads over plain http (no SSL certificate), or when the certificate is expired or misconfigured. It is Chrome telling your visitors their connection to you is not encrypted.
The three usual causes
- No certificate at all: the site has never been set up with SSL. Fix: install one (free) and redirect http to https.
- An expired certificate: it was working, then renewal failed. This one shows visitors a full-page red warning. Fix: renew, and switch on auto-renewal so it cannot recur.
- Mixed content: the page is https but something inside it (often an image) still loads over http. The padlock downgrades. Fix: update those links to https.
Does it actually cost you business?
Yes, measurably. Most people will not type a phone number or fill in a form on a page their browser has just told them is insecure, and many bounce straight back to the search results, which also signals Google that your result was not helpful.
Whose job is it to fix?
Your hosting company or whoever looks after your website. It is typically a 15-minute job for the first two causes. If a site of yours says Not Secure right now, it is worth a message today rather than someday.
The takeaway
- Not Secure means no encryption: missing, expired or broken SSL.
- Expired certificates show a full-page warning that turns visitors away.
- It is usually a quick fix for your host or web person.
Want it handled instead of explained?
Everything in this article is included and looked after in every site I build. One monthly plan, no jargon, no surprises.
Start a project