Why does my website say "Not secure"?

First, identify the warning

Open your website using:

https://yourdomain.co.za

Replace yourdomain.co.za with your own domain.

What happens next?

  • If the HTTPS version works securely but the HTTP version does not redirect, the certificate is working. Your website still needs an HTTPS redirect.
  • If the browser reports an invalid, expired or mismatched certificate, continue with the checks below.
  • If the page loads over HTTPS but some content is insecure, see Check for mixed content below.

1. Check where the domain points

Webway issues free SSL certificates automatically:

  • cPanel accounts use AutoSSL.
  • DirectAdmin accounts use Let's Encrypt.

The certificate can only be issued once the domain points to the correct Webway hosting server.

Check both:

  • yourdomain.co.za
  • www.yourdomain.co.za

Both names must resolve to the Webway hosting server if the certificate should cover both.

If you recently changed nameservers or DNS records, allow time for DNS propagation before trying again.

2. Check for an incorrect AAAA record

An A record points a domain to an IPv4 address. An AAAA record points it to an IPv6 address.

If an AAAA record points to a different server, certificate validation may reach that server instead of Webway.

Update or remove the incorrect AAAA record only if your website does not use that IPv6 address. Ask Webway Support if you are unsure.

3. Check whether Cloudflare is proxying the domain

When Cloudflare's proxy is enabled, public visitors connect to Cloudflare before reaching Webway. The certificate shown to visitors and the certificate installed on the Webway server are separate.

If the Webway certificate cannot be issued:

  1. Open the domain's DNS settings in Cloudflare.
  2. Find the records for the main domain and www.
  3. Temporarily change them from Proxied to DNS only.
  4. Wait for the DNS change to take effect.
  5. Request the certificate again.
  6. Re-enable the proxy after confirming that HTTPS works at the Webway server.

If changing the proxy could interrupt a live website, contact Webway Support first.

4. Check CAA records

CAA records restrict which certificate authorities may issue certificates for a domain.

Webway's free certificates on both cPanel and DirectAdmin come from Let's Encrypt. If your domain has CAA records, one of them must allow letsencrypt.org, or the certificate can't be issued.

Do not remove a CAA record unless you understand why it was added. If you're unsure, send your current CAA records to Webway Support.

5. Check that www exists

The main domain and www are different DNS names.

For a certificate to cover both:

  • The main domain must point to the Webway server.
  • www must also point to the Webway server.

If www is missing or points elsewhere, the panel may issue a certificate only for the main domain or report a validation failure.

Request the certificate again in cPanel

  1. Sign in to cPanel.
  2. Open SSL/TLS Status under Security.
  3. Confirm that the affected domain and www are included in AutoSSL.
  4. Select Run AutoSSL.
  5. Wait for the process to finish.
  6. Review any error shown beside the domain.

If Run AutoSSL is not available, wait for the automatic run or contact Webway Support.

Request the certificate again in DirectAdmin

  1. Sign in to DirectAdmin.
  2. Open SSL Certificates for the affected domain.
  3. Choose the free automatic certificate option.
  4. Include both the domain and www.
  5. Save or request the certificate.
  6. Review any validation error shown by DirectAdmin.

DirectAdmin menu labels can differ slightly between interface versions.

Check for mixed content

Mixed content occurs when an HTTPS page loads images, scripts, fonts or stylesheets through an old http:// address.

The main certificate may be valid, but the browser can still warn that parts of the page are insecure.

To fix it:

  1. Open the page using HTTPS.
  2. Check the browser's developer console for mixed-content warnings.
  3. Update affected resource addresses from http:// to https://.
  4. Update the website's configured address if it still uses HTTP.
  5. Clear the website, LiteSpeed and browser caches.
  6. Test the page again.

For WordPress, check both the WordPress Address and Site Address, along with URLs saved by the theme or page builder.

Enable HTTPS redirects only after SSL works

Do not force every visitor to HTTPS until the certificate is valid.

Once HTTPS works correctly, enable a redirect from HTTP to HTTPS so visitors always use the secure version.

Still stuck?

Open a support ticket and include:

  • Your domain name
  • Whether you use cPanel or DirectAdmin
  • The exact certificate or browser error
  • Whether the main domain, www or both are affected
  • When you last changed the domain's DNS
  • Whether you use Cloudflare
  • Any A, AAAA and CAA records configured for the domain
  • A screenshot of the panel's SSL error

Did this answer it?