Common causes
- The certificate covers example.com but not www.example.com, or the reverse
- The request hits the default virtual host, which serves another site's certificate
- DNS points the hostname at a server or CDN that has no certificate for it
- A wildcard *.example.com is used for the bare domain or a deeper level like a.b.example.com
- Visiting the server by IP address or an internal hostname not on the certificate
- Shared hosting serving the host's own certificate because SSL was never installed for the domain
How to fix it
- See which names the certificate covers. Run echo | openssl s_client -connect example.com:443 -servername www.example.com 2>/dev/null | openssl x509 -noout -subject -ext subjectAltName. The hostname you visit must appear in the DNS: list.
- Issue a certificate for all names. With Certbot run sudo certbot --nginx -d example.com -d www.example.com (or --apache). On cPanel, make sure both names are included and run AutoSSL.
- Make sure the right vhost answers. Check that server_name (Nginx) or ServerName/ServerAlias (Apache) on the port 443 block includes the hostname. Otherwise the default server's certificate is sent.
- Check DNS and CDN. Confirm with dig +short www.example.com that the name points where the certificate is installed. On a CDN, add the hostname to the edge certificate.
- Redirect extra names after HTTPS works. A redirect from www to non-www over HTTPS still needs a certificate for www, because the TLS handshake happens before the redirect.
Shell (Certbot + inspection)
echo | openssl s_client -connect example.com:443 -servername www.example.com 2>/dev/null \
| openssl x509 -noout -subject -ext subjectAltName
sudo certbot --nginx -d example.com -d www.example.com How to stop it happening again
- Always include both bare and www names when issuing certificates
- Add new subdomains to the certificate before pointing DNS at the server
- Give each site an explicit server_name or ServerAlias on port 443
- Monitor every public hostname with a certificate check, not just the main one