What an SSL certificate actually does
An SSL certificate is a small file installed against a domain that lets a browser confirm two things: that the domain is who it claims to be, and that the connection to it is encrypted. The padlock next to a web address, and https instead of http, both come directly from a valid certificate being in place. Without one, a browser has no way to verify either of those things.
Key takeaways
- An SSL certificate is what turns http into https and puts the padlock next to a web address. It proves a domain is who it claims to be and encrypts the connection to it.
- Certificates are not permanent. They expire on a fixed schedule, and when renewal is a manual step someone has to remember, it is usually a customer who notices first, not the team running the domain.
- Renewal does not need a person tracking dates in a spreadsheet. A domain platform that issues and renews certificates automatically removes the single most common way SSL breaks.
The certificate itself is issued by a certificate authority, a third party that checks a domain is genuinely controlled by whoever is requesting the certificate, then signs a file that other browsers trust automatically. This is what stops anyone from simply claiming to be a domain they do not own.
SSL is easy to confuse with hosting, and the two are separate things. Hosting is where a page's files live and how it gets served. An SSL certificate is about proving identity and encrypting the connection once a visitor arrives. A domain used only for email, or only to point at a booking page, still needs a valid certificate the moment anything on it is reached over https, which is the default nearly every browser now expects.
Why a missing or expired certificate is a real problem
Modern browsers do not quietly tolerate a missing or expired certificate. Chrome, Safari, and Firefox all show a full-page warning, something like "Your connection is not private" or "This connection is not secure", before a visitor can even see the page. Most people do not click through a warning like that. They leave, and they do not always come back to try again later.
For a business domain, that visitor might be a prospect clicking a booking link from a sales email, or a customer following a link from a support ticket. The warning does not say "technical hiccup". It reads as the site being unsafe, which is a worse first impression than the page simply being slow or briefly down.
| Certificate state | What a visitor sees | What it costs you |
|---|---|---|
| Valid | Padlock, no warning, page loads normally | Nothing, this is the baseline |
| Expired | Full-page security warning before the site loads | Lost clicks, lost trust, support tickets asking if you were hacked |
| Missing entirely | Browser refuses the connection outright on https | The page is effectively unreachable for most visitors |
Search engines also treat https as a baseline signal, not a bonus. A domain serving content without a valid certificate is at a real disadvantage before ranking factors like content quality even come into play. None of this is optional anymore. It is closer to a domain simply not resolving.
How certificates get issued, and why renewal is the risky part
Getting a first certificate is usually the easy part. A certificate authority verifies control of the domain, often by checking a specific DNS record or a file placed on the domain, then issues a certificate valid for a fixed window.
That window is the part that causes problems later. Certificates are not valid forever, and modern automated certificate authorities commonly issue them for around ninety days rather than the year or more that older paid certificates used to run. Shorter validity periods are better for security, since a compromised certificate has less time to be useful to an attacker, but they also mean renewal has to happen far more often than most teams expect.
This is where a certificate that was fine at issuance quietly becomes a liability. Nobody notices a certificate approaching its expiry date. Nobody gets paged for it the way they would for a server going down. It just sits there counting down until the day it lapses, and by then the warning is already showing to visitors.
Common mistakes that let certificates lapse
SSL renewal is simple in theory. In practice, a handful of avoidable mistakes account for almost every expired-certificate incident.
- Treating renewal as a manual, occasional task. A certificate that renews once a year is easy to forget. One that needs renewing every ninety days and is still handled by hand fails on a much shorter clock.
- No owner once the person who set it up leaves. A certificate configured by someone who has since left the company has no one watching its expiry date at all.
- Certificate issued for the wrong hostname. A certificate covering example.com but not www.example.com, or missing a subdomain like a booking page, throws the same warning on the addresses it does not cover.
- No monitoring or alerting. Without something actively checking expiry dates, the first signal is a visitor reporting the warning, which is the most expensive way to find out.
- Assuming a platform handles it without confirming that it actually does. Not every host or DNS provider renews automatically by default. Some require re-enabling auto-renewal after any change to the domain's settings.
Every one of these is a process failure, not a technical one. The certificate technology itself rarely fails. The tracking around it does.
How to check a certificate before it becomes a problem
Checking whether a certificate is valid and how long it has left takes under a minute and does not require any special access.
- Click the padlock in your browser. Every major browser shows certificate details, including the expiry date, when you click the padlock icon next to the address bar.
- Use a free SSL checker. A browser-based SSL checker tool shows the same information without needing to visit the site itself, useful for checking a domain before a link to it goes out in a campaign.
- Check every hostname separately, not just the main domain. A booking page or a custom email login screen on a subdomain can have its own certificate status, separate from the main website.
- Set a recurring reminder if nothing is monitoring automatically. With ninety-day certificates, a quarterly manual check is the bare minimum, and it is still worse than not having to check at all.
Why automatic renewal is worth insisting on
Manual certificate renewal does not scale past one domain. A mid-market or enterprise team is rarely managing just one. Between the main website, regional domains, a custom booking page, and a custom email login, a single company can easily have half a dozen hostnames that each need a valid, current certificate, on a schedule that repeats every few months rather than once a year.
The fix is not a better spreadsheet. It is not needing to track expiry dates at all. When a domain platform issues and renews certificates itself the moment a domain is connected, whether that domain points at a custom email login or a booking page, there is no calendar reminder to set and no manual renewal step to forget.
WeldHost issues and renews the SSL certificate automatically for every domain connected through it, alongside the DNS records and domain registration it already manages. Connect a domain once, and there is no certificate expiry date left for anyone to track by hand. It is part of the WeldSuite complete software suite, at $49 a month on Business or $69 on Scale, with everything, including AI, included at every tier.
Sources
Frequently asked questions
What is an SSL certificate in simple terms?
An SSL certificate is a file tied to a domain that proves the domain's identity to a browser and encrypts the connection to it. It is what turns http into https and puts the padlock next to a web address. Without a valid certificate, a browser cannot confirm either of those things.
What happens when an SSL certificate expires?
Browsers show a full-page security warning before the page loads, something like "Your connection is not private". Most visitors do not click through it. The site or page becomes effectively unusable for new visitors until the certificate is renewed, even though nothing else about the page has changed.
How often do SSL certificates need to be renewed?
It depends on the certificate authority, but modern automated certificates commonly last around ninety days rather than the year or more that older paid certificates used to run. Shorter validity periods are more secure, but they also mean renewal has to happen far more often, which is why manual renewal fails more easily than it used to.
Is SSL the same thing as hosting?
No. Hosting is where a page's files live and how it is served. An SSL certificate proves the domain's identity and encrypts the connection once a visitor arrives. A domain used only for email or only for a booking page still needs its own valid certificate for anything reached over https.
Can SSL certificates renew automatically?
Yes, and for any domain used for business purposes, automatic renewal should be the default rather than something checked manually. A domain platform that issues and renews certificates itself the moment a domain is connected removes the tracking and the manual step entirely.
See it all work together
WeldSuite brings CRM, helpdesk, accounting, mail, projects and more into one connected platform. Change something once and it shows up everywhere.