Certificates, DNS and domains
Certificate warning in the browser
Usually: Expired certificate, a name that is not covered, a missing intermediate, or a mismatch between the www and bare versions.
- Click the warning details to see which problem it is.
- Run an online SSL checker for the whole chain.
- Make sure the certificate lists both the bare domain and www.
- Check that auto-renewal is still working.
Site works for me but not for others
Usually: DNS caching, a stale AAAA record, regional routing problems, or a CDN edge issue.
- Check DNS from several resolvers.
- Look for an old IPv6 record.
- Test from a mobile network.
- Ask the person for the exact error message or a screenshot.
Mixed content warnings
Usually: A page loaded over HTTPS includes images or scripts over plain HTTP.
- Look for http:// URLs in the page source.
- Update the site URLs in the database.
- Fix hard-coded links in the theme.
Domain suddenly stopped working
Usually: Expiry, a registrar suspension, or a nameserver change.
- Check the domain status with a WHOIS lookup.
- Look for notices at the registrar.
- Compare the registrar's nameservers with your DNS provider.
NET::ERR_CERT_COMMON_NAME_INVALID
Usually: The certificate does not list the name you typed.
- Open the certificate details and read the names.
- Reissue with both the bare domain and www, or use a certificate that covers the subdomain.
- Check that the server presents the right certificate for the host.
The certificate is valid but some phones reject it
Usually: The intermediate certificate is missing from the chain your server sends.
- Install the full chain from your authority.
- Test with an online checker that follows the chain strictly.
- Reload the web server after changing the files.
DNS_PROBE_FINISHED_NXDOMAIN
Usually: The name does not exist in DNS, or the resolver has cached a negative answer.
- Check that the record exists in the zone.
- Check the registrar's nameservers match the DNS provider.
- Wait for negative caching to expire or test from another network.
Site loads by IP address but not by name
Usually: DNS records are wrong, missing or not yet visible.
- Query the records with dig.
- Check the nameserver delegation at the registrar.
- Confirm that the domain has not expired.
Subdomain does not work
Usually: No DNS record for it, or the server has no virtual host for that name.
- Create an A or CNAME record for the subdomain.
- Add the subdomain in your hosting panel.
- Issue a certificate that covers it.
Browser keeps showing the old certificate
Usually: The server was not reloaded, the wrong virtual host holds the old files, or a CDN or proxy presents its own.
- Reload or restart the web server.
- Check which server actually answers on port 443.
- Test from outside with an SSL checker.