"SSL certificate name mismatch" (NET::ERR_CERT_COMMON_NAME_INVALID) on your site

Your server sent a security certificate, but it was made for a different name. The browser asked for yoursite.com and got a certificate for www.yoursite.com, or for your host's own domain. It refuses to trust it.

What to do, in order

  1. Check which name fails. Try both yoursite.com and www.yoursite.com. Often one works and the other does not. The certificate must cover both.
  2. Reissue the certificate with both names. In cPanel, run AutoSSL again. With Let's Encrypt, run certbot --nginx -d yoursite.com -d www.yoursite.com. On Cloudflare, check the edge certificate lists both.
  3. Check the DNS points to the right server. If one name still points at an old host, that old host answers with its own certificate. Run dig +short www.yoursite.com and compare with dig +short yoursite.com.
  4. Website builders (Squarespace, Wix, Shopify): remove the domain and add it again in the builder's domain settings. The certificate is issued again within a few hours.
  5. Redirect the other name. Once both are covered, send every visitor to one version with a single 301 redirect.

If it still fails, send me the address and I will tell you which name is wrong.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.