Not secure in the address bar, and mixed content in the console, are two different jobs.
- Not secure (or a full-page certificate warning) means the browser did not accept a certificate for this name. The page is still on HTTP, or the certificate is missing, expired, or for a different hostname.
- Mixed content means the page itself loaded over HTTPS, then asked for an image, script, stylesheet, or font over plain
http://. The padlock is there, then the browser warns or blocks those files.
On Beginner and Standard shared hosting (cPanel) in Australia, AutoSSL issues a Let's Encrypt certificate once the name points at this account. Open cPanel from the portal. Do not guess a hostname.
On a VPS, install TLS yourself with Certbot. Credentials and the console are on that server in the portal.
On a dedicated server, open a support ticket and we will walk you through a certificate.
Unsure which warning you have, or a step is unclear? Open a support ticket and we will help.
Background: Understanding SSL/TLS and HTTPS.
See what the browser is telling you
- Open the exact URL visitors use, including
wwwif that is how people type it. - Look at the address bar.
- Click the padlock, the warning icon, or the Not secure label and read the certificate details.
Typical cases:
| What you see | What it usually means | Where to start |
|---|---|---|
Not secure on http://yourdomain.com | No HTTPS redirect, or no certificate yet | Shared hosting: AutoSSL, then Force HTTPS Redirect |
| Full-page warning, name does not match | You opened a hostname the certificate does not cover | Confirm DNS, then run AutoSSL for that name |
| Full-page warning, expired | The certificate on this name has lapsed | Shared hosting: run AutoSSL again. VPS: renew with Certbot |
| Padlock, but images or layout missing | Mixed content: leftover http:// files | Fix the URLs on the site |
| Padlock, console shows mixed content | Same as above, even if the page still looks fine | Fix the URLs on the site |
You can also open Developer Tools (F12, or right-click then Inspect), then the Console tab. Mixed content is listed there with the exact http:// URL the page requested.
To read the public certificate from outside your own cache, use SSL Labs. Enter the hostname. Wait for the grade. A missing or unmatched name shows up there even when your laptop still has an old answer.
Shared hosting: issue or refresh the certificate
The name must already resolve to this account. AutoSSL proves control over HTTP. If DNS still points elsewhere, no certificate is issued.
If the domain is registered with us, it is already on AtlasDNS. Open Domains → the domain → DNS in the portal and keep the A records for @ and www on this account's shared IP (cPanel General Information → Shared IP Address).
If the domain is registered elsewhere, set its nameservers to ours, then manage records in the portal:
ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au
AtlasDNS is the default. Do not send the domain to a third-party DNS host. Full steps: Point your domain at your hosting. Changes are often quick, but they can take a while to show everywhere. See DNS propagation explained.
Then:
- Sign in at the portal, open the hosting service, and click Log in to cPanel.
- Open SSL/TLS Status.
- Find the domain and
www(and any addon, alias, or subdomain you need). - Run AutoSSL if a certificate is not there yet, or if the row is expired or missing names. Wait for a valid cert on that row.
- In cPanel Domains, turn Force HTTPS Redirect on for that name.
- Visit
https://yourdomain.comandhttps://www.yourdomain.comin a private window.
You do not need a 301 in Redirects for same-host HTTP to HTTPS. See Set Up a Domain Redirect. Do not paste a RewriteRule into .htaccess as the first HTTPS step. Force HTTPS Redirect is the control on this hosting.
Stay on AutoSSL. Do not buy a certificate from another CA as the first step. If you already have a certificate and key file we need to install, open a support ticket.
Skip CAA records unless you have a reason. A CAA that names the wrong issuer stops AutoSSL. If you want one set, open a support ticket. See DNS record types explained.
If SSL/TLS Status still shows no certificate after the name has resolved here, open a support ticket. Tell us the domain.
You do not restart Apache on shared hosting. AutoSSL installs the certificate on the account. After a valid row appears, reload the site in a private window.
The name on the certificate must match the URL
AutoSSL issues Domain Validation certificates for the specific names on this account that already resolve here (the apex, www, addons, aliases, subdomains). It does not issue a * wildcard.
If the warning says the certificate is for a different hostname:
- Click the warning and read the names the certificate covers.
- Confirm you are visiting a name that is supposed to live on this account.
- For a new subdomain, addon, or alias, add it in cPanel first, point DNS at this account, then run AutoSSL again on SSL/TLS Status.
- Check both the apex and
www. Visitors often type one while the certificate only has the other until AutoSSL has run for both.
Do not delete a working certificate as a first try. Run AutoSSL for the name you actually use.
VPS
There is no AutoSSL on a stock VPS. Install a certificate on the server. Certbot (Let's Encrypt) is the usual path: Get a Free SSL Certificate with Certbot.
Point the name at the VPS IPv4 shown on that service in the portal first. Open 80 and 443 on the host firewall. See Set up a UFW firewall on Ubuntu and First steps on a new VPS.
After Certbot installs a certificate it reloads the web server for you. If you edited the vhost by hand, reload Apache or Nginx from the shell on that VPS.
An expired Certbot certificate usually means the renewal timer is off. Follow the renewal section in the Certbot article, or open a support ticket and we will walk through the server with you.
Mixed content: the page is HTTPS, the files are not
Once the padlock is there, leftover http:// URLs are the usual reason the browser still complains. Scripts and stylesheets loaded over HTTP are often blocked. Images may show a warning and still appear, or they may not.
Force HTTPS Redirect sends visitors to https://. It does not rewrite http:// URLs inside the page. Those leftover addresses are mixed content.
Find the insecure URL
- Open the site over
https://. - Open Developer Tools (F12), then Console.
- Look for a line that names an
http://image, script, stylesheet, or font. - Note that URL. That is the file you need to change.
HTML and static files
- Sign in at the portal, open the hosting service, and click Log in to cPanel.
- Open the File Manager on the site's document root (
public_htmlfor the primary domain). - Search for
http://. - Change resource URLs (images, CSS, JS, fonts, embeds) to
https://when that host actually serves HTTPS. Prefer a root-relative path (/images/logo.png) when the file lives on this site. - Save and reload in a private window.
Do not change http:// inside comments, example text, or a third-party endpoint that is HTTP-only. If an external host has no HTTPS, replace that asset or drop it.
An FTP client works the same way. See Create an FTP Account and Connect.
WordPress
- In cPanel Domains, turn Force HTTPS Redirect on.
- In WordPress go to Settings → General. Set WordPress Address and Site Address to the
https://URLs, then save. - Posts, widgets, and theme options often still store the old
http://site URL. Prefer a tool that understands serialised PHP. A raw replace in every table can break widgets. Better Search Replace (Plugins → Add New) is the usual in-dashboard tool. Findhttp://yourdomain.comand replace withhttps://yourdomain.com. Run a dry run first. - Hardcoded
http://in the active theme or a custom plugin still needs a File Manager edit.
Prefer WordPress Toolkit or Installatron for a new site. More HTTPS steps: Secure Your WordPress Site. Moving a site and rewriting URLs: Back Up and Migrate a WordPress Site.
To change only the two core options (home and siteurl) while you get into wp-admin, use phpMyAdmin. Then finish the rest of the URLs with Better Search Replace.
If you are not comfortable changing the database, open a support ticket. Tell us the domain. We will help.
Embeds and third-party files
- Images on another domain: use that host's
https://URL, or upload the file to this account. - Fonts, maps, videos, analytics, and ads: use the current HTTPS embed from that service.
- Old
http://video, map, or font links are a common leftover after a site is moved to HTTPS.
A page that only works because mixed content is allowed is not finished. Fix the URLs.
Verify the fix
- Open
https://yourdomain.comandhttps://www.yourdomain.comin a private window. - Confirm the padlock. The certificate should match the name, show a future expiry, and name a trusted CA (Let's Encrypt on AutoSSL and Certbot).
- Open the console again. Mixed-content lines should be gone.
- Optional: run the hostname through SSL Labs.
If the padlock is missing only on your PC, flush the local DNS cache and try another network. See This site can't be reached.
What renews on its own
- AutoSSL renews Let's Encrypt certificates on shared hosting. You do not upload a file or mark a calendar date.
- Certbot on a VPS renews with its timer. Keep that timer enabled.
- A certificate we installed from a file you supplied does not renew itself. Open a support ticket before it expires if you need a replacement installed.
If a site collects a login, an email, or a card number, leave Force HTTPS Redirect on.
Need hosting first? Browse shared hosting, VPS, or dedicated. After the account is ready: Getting started after you order hosting.
If it is still not secure
Open a support ticket and include:
- The exact URL (apex,
www, or subdomain) - Whether you see Not secure, a full-page warning, or mixed content
- The wording from the browser or the console
- Whether SSL/TLS Status already shows a valid certificate (shared hosting)
- Any recent DNS, domain, or site-URL change
We will check the certificate and the leftover URLs with you.
Do not wait on an email thread. Open a support ticket and we will help.
Related
- Understanding SSL/TLS and HTTPS
- Keep your website secure
- Point your domain at your hosting
- DNS record types explained
- DNS propagation explained
- This site can't be reached
- Set Up a Domain Redirect
- Use the File Manager
- Manage a Database with phpMyAdmin
- Create an FTP Account and Connect
- Create a Subdomain
- Add an Addon Domain
- Create an Alias (Parked Domain)
- Install WordPress
- Secure Your WordPress Site
- Back Up and Migrate a WordPress Site
- Get a Free SSL Certificate with Certbot
- Set up a UFW firewall on Ubuntu
- First steps on a new VPS
- Getting started after you order hosting