What to do if…
your website suddenly shows a security or certificate warning and you did not change anything
Short answer
Treat it as a real incident until you have proved it is not. Stop users from logging in, paying, or submitting sensitive forms, then check whether the warning is caused by an expired, wrong, unexpectedly issued, or misconfigured certificate, DNS/CDN changes, or compromise.
Do not do these things
- Don’t click through the warning to “proceed anyway” on admin, login, or payment pages.
- Don’t switch random SSL, TLS, CDN, or proxy settings without writing down the current settings first.
- Don’t follow certificate renewal links from emails, pop-ups, or third parties you did not initiate.
- Don’t change DNS records in a rush unless you know what you are changing and how to revert it.
- Don’t rotate every credential at once before securing the accounts that control DNS, CDN, hosting, registrar access, and admin access.
- Don’t delete logs, old certificates, DNS history, audit entries, or suspicious user accounts before recording what you found.
What to do now
-
Pause risky user actions.
If you can, temporarily disable logins, checkout, password resets, and forms that collect personal or payment details. A plain maintenance message is enough while you check. -
Confirm the warning is on your real domain.
Carefully read the exact domain in the address bar and in the browser warning. If it is a look-alike domain or an unexpected subdomain, stop using it and treat it as phishing or impersonation. -
Check whether it is everyone or just one device.
Test from a second device and a different network, such as mobile data. If it only happens on one device or network, check for a wrong system clock, a work network or security software intercepting HTTPS, a captive portal, or a local device issue. -
Check the common certificate causes first.
- Check the certificate expiry date shown in the browser details.
- Check that the certificate name matches your exact domain or expected subdomain.
- Check that the certificate issuer is one you expect.
- Check that the server or platform time is correct.
-
Check what certificate the public internet is receiving.
Use your hosting dashboard, CDN dashboard, certificate authority account, or a trusted external TLS checker. Record the time, hostname, certificate issuer, expiry date, and whether the certificate chain is complete. -
Look for changes you did not make.
- In DNS, check recent A, AAAA, CNAME, CAA, and nameserver changes for the affected hostname.
- In your CDN or proxy, check whether proxying, SSL/TLS mode, origin certificate settings, or custom certificates changed.
- In hosting or the web server, check which certificate is selected for the affected site.
- In your registrar, check whether nameservers, contacts, or login activity changed.
-
If it looks expired or misconfigured, restore a valid certificate carefully.
- Renew or reissue through your normal certificate authority, hosting platform, or CDN.
- Install or select the certificate for the exact affected hostname.
- Remove or de-select expired or wrong certificates where your platform allows it.
- Re-test from a clean device and a different network.
-
If anything looks like compromise, contain first.
Treat unexpected DNS records, unknown admin users, unknown API keys, unexpected redirects, unfamiliar certificates, or unexplained certificate orders as warning signs. Secure registrar, DNS, CDN, hosting, and admin accounts; enable MFA where available; revoke unknown sessions and API keys; and preserve CDN, WAF, server, DNS, registrar, and admin logs before they roll over. -
If personal data might have been exposed, start a breach-risk note now.
Record when you first became aware, what hostnames and systems may be affected, what user actions were possible, and what you have done to reduce harm. If a personal data breach is likely to risk people’s rights and freedoms, UK GDPR reporting to the ICO is generally required as soon as possible and, where feasible, within 72 hours. -
Use UK reporting routes if you suspect attack or fraud.
- Use the NCSC reporting portal or the GOV.UK cyber incident signposting service if you believe your organisation has been compromised.
- Use Report Fraud for cyber crime or fraud reporting in England, Wales, or Northern Ireland.
- If your business, charity, or organisation is under a cyber attack in England, Wales, or Northern Ireland, Report Fraud lists 0300 123 2040 for immediate advice.
- If the incident is in Scotland, use Police Scotland’s cybercrime reporting routes. Call 999 if there is a threat to life or national infrastructure.
What can wait
- You do not need to decide today whether to change host, redesign the site, or rebuild your security architecture.
- You do not need perfect root-cause proof before pausing risky user actions and restoring a valid certificate.
- You do not need a polished public statement immediately. If users are affected, a short holding message such as “We are investigating a security issue; sign-in and purchases are temporarily limited” is enough for now.
- You do not need to rotate every application secret until the accounts that control DNS, CDN, hosting, registrar access, and admin access are secured.
Important reassurance
Certificate warnings often have ordinary causes, such as expiry, an incomplete chain, wrong certificate selection, CDN settings, DNS changes, or clock problems. They can also be a sign of compromise, so taking a careful pause now is a sensible way to protect users and avoid making the outage worse.
Scope note
These are first steps to stabilise the situation and reduce harm. If you suspect compromise, certificate misuse, fraud, or customer data exposure, later decisions may need specialist cyber incident response, legal, privacy, or insurance support tailored to your setup.
Important note
This is general information, not legal, professional security, financial, insurance, or technical advice. If you are unsure whether your site or accounts are compromised, prioritise user safety, preserve evidence and logs, and get qualified help.
Additional Resources
- National Cyber Security Centre — Provisioning and managing certificates in the Web PKI
- GOV.UK — Reporting a Cyber Security Incident
- GOV.UK — Where to Report a Cyber Incident
- GOV.UK — Where to Report a Cyber Incident
- Police.uk — Reporting a fraud
- Information Commissioner's Office — UK GDPR data breach reporting (DPA 2018)
- Police Scotland — You’ve accepted all cookies
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.