When Do SSL Certificates Expire? Key Dates

August 25, 2026
//
When Do SSL Certificates Expire? Key Dates

A browser warning can stop a potential customer before they read a single word on your website. If you are asking, when do SSL certificates expire?, the practical answer is: on the exact expiration date embedded in the certificate, often sooner than many site owners expect. Missing that date can make a working website appear unsafe, even when your hosting, domain, and website files are all functioning normally.

SSL certificates protect the connection between a visitor’s browser and your website. They enable HTTPS, encrypt information such as contact form submissions and login details, and help browsers confirm that visitors are connected to the real website. Keeping a certificate current is therefore a routine part of managing a dependable online presence.

When Do SSL Certificates Expire?

Every SSL certificate has a start date and an end date. The end date is set when the certificate is issued and cannot be extended after issuance. Once that time passes, browsers can no longer treat the certificate as valid.

For publicly trusted SSL certificates, the maximum validity period is generally 398 days, or roughly 13 months. Many certificate providers issue certificates for one year at a time. Others, especially automated certificates, may have much shorter lifetimes of 90 days. A shorter validity period is not necessarily a problem. It can improve security by encouraging regular validation and reducing the time a compromised certificate could be used.

The date that matters is the certificate’s actual expiration date, not the date you purchased an SSL plan or renewed a related hosting service. A multi-year SSL purchase may cover multiple annual certificate issuances, but the live certificate installed on your server can still need renewal each year.

What Happens When an SSL Certificate Expires?

When visitors open a website with an expired certificate, their browser usually displays a prominent security warning. The wording differs by browser, but it may state that the connection is not private or that the certificate has expired. Visitors must make an extra effort to continue, and many will not.

For a business site, the result can be immediate: lost inquiries, abandoned purchases, reduced confidence, and support requests from customers who think the website has been hacked. A small padlock issue can have a large commercial effect because it occurs at the point where trust matters most.

An expired SSL certificate does not usually take your website offline. Your web server, email inboxes, domain registration, and hosting account may continue operating. However, HTTPS access becomes untrusted. This distinction is useful when troubleshooting because renewing a domain name will not fix an expired certificate, and renewing a certificate will not fix an expired domain.

How to Check Your SSL Certificate Expiration Date

The fastest way to check is in a browser. Visit your website using HTTPS, select the padlock or site information icon near the address bar, and view the certificate details. Look for a field such as “Valid to,” “Expires on,” or “Certificate validity.”

You can also check from your hosting control panel or SSL management area. This is often the better option if you manage several domains, subdomains, or client websites. It lets you see which certificates are active, which are pending installation, and which are approaching expiration.

If you manage websites from the command line, server tools can retrieve certificate details directly. That approach is useful for developers and larger environments, but business owners do not need technical access to stay informed. What matters is having a clear record of every certificate, the domain it covers, and its renewal date.

Do not assume that www and non-www versions are always covered in the same way. For example, a certificate for example.com may not automatically cover www.example.com unless both names were included during issuance. Wildcard certificates also have different coverage rules. Checking the live certificate prevents assumptions from becoming visitor-facing warnings.

How Early Should You Renew an SSL Certificate?

Renew at least 30 days before expiration when possible. This gives you time to complete validation, address a DNS or email approval issue, install the renewed certificate, and test the website before the old certificate ends.

For an organization with online payments, customer portals, booking forms, or multiple stakeholders, 45 to 60 days is more comfortable. The renewal itself may be quick, but the surrounding work can take longer. Your DNS contact email may be outdated, a domain validation record may need updating, or a developer may need to install the certificate on a separate server.

Renewing early does not usually waste the remaining time on your current certificate. In many commercial SSL renewal processes, the unused validity time is accounted for within the permitted certificate lifetime. Still, confirm the issuer’s process, particularly if you use an unusual certificate type or manage a high number of domains.

Why SSL Renewals Sometimes Fail

A certificate renewal is not always automatic simply because payment was successful. The certificate authority must validate control of the domain again. For domain-validated certificates, this is commonly done through a DNS record, a file placed on the website, or an approval email sent to an authorized address.

Renewals can fail when a website has moved to a new hosting provider, DNS is managed elsewhere, or the domain’s contact information is no longer current. A web developer may also renew a certificate but install it on an old server, leaving the live site to present the expired certificate.

Automation reduces this risk, especially for 90-day certificates. However, automation needs monitoring. An automated renewal can fail if DNS permissions change, a firewall blocks validation, or the server configuration is altered. Set expiration alerts even when renewals are automated. Alerts are a backup, not an inconvenience.

A Simple SSL Expiration Management Routine

For one website, add two reminders to your calendar: one 60 days before expiration and another 30 days before. Record the certificate provider, validation method, hosting account, and the person responsible for approval. That small amount of documentation is valuable when a team member is unavailable or a developer changes.

For multiple domains, keep a simple certificate inventory. Include the domain name, certificate type, expiration date, server or hosting location, renewal method, and account owner. Review it monthly. This is particularly helpful for agencies, designers, and growing businesses that manage client sites alongside their own.

After renewal, test the live website in a private browser window. Confirm that HTTPS loads without warnings, the certificate shows the new expiration date, and key pages such as forms, checkout pages, and login areas work as expected. If your website uses a content delivery network, load balancer, or separate mail server, verify that each relevant service is using the correct updated certificate.

SSL Expiration and Your Domain Renewal Are Different

Domain names and SSL certificates are related, but they renew on separate schedules. A domain registration controls your right to use a name such as yourbusiness.mu or yourbusiness.com. An SSL certificate verifies and encrypts connections to that name. Your hosting service provides the server where the website operates.

Each service can expire independently. A site might have an active domain and hosting plan but an expired SSL certificate. It might also have a valid certificate but a domain that has expired and no longer directs visitors to the server. Managing all three renewal dates together is the safest approach.

A provider that keeps domains, hosting, and SSL services easy to view in one account can make this routine simpler. Raphus customers can use a centralized service approach to reduce the chance that an essential renewal is overlooked, while still retaining clear control over their digital assets.

The best time to think about an SSL certificate expiration date is not when a browser warning appears. Put the date in your renewal routine, allow enough time for validation, and treat the final test as part of publishing a trustworthy website. Your visitors should see your business, not a security alert.