Fix Wix SSL Expiry in 6 Steps for Small Teams, Gather Evidence First
By Nick Phillips, Founder
Fix Wix SSL Expiry in 6 Steps for Small Teams, Gather Evidence First

Wix supplies and renews SSL certificates for Wix-hosted sites automatically, so you shouldn’t need to buy or install one yourself. If your browser shows an expired certificate warning anyway, that’s almost always a symptom of a DNS or hostname problem rather than a lapse on Wix’s end. Run the quick checks below first. If they come up clean, gather the evidence and contact Wix support.
TL;DR:
- Most SSL expiration warnings on Wix sites are caused by DNS or hostname mismatches, not actual certificate lapses managed by Wix.
- Common issues include inconsistent DNS pointing between apex and www domains, CAA record conflicts, delayed DNS propagation, or leftover old DNS entries from previous hosting.
- Checking your site’s SSL status involves verifying the certificate’s actual expiry with crt.sh, reviewing DNS records, and confirming proper domain connection in Wix dashboards before contacting support.
- Shortening certificate validity periods due to industry rules starting in 2026 will increase renewal frequency, emphasizing the importance of DNS hygiene and proactive monitoring tools.
- Automated monitoring services, like Otterwatch, provide early SSL expiry alerts via email, helping small teams prevent disruptions without complex dashboards.
Table of Contents
- How to check your Wix site’s SSL status
- Common causes for a Wix SSL to show as expired
- If your Wix SSL is expired: a prioritized remediation checklist
- Certificate lifetimes and industry changes to watch for in 2026
- Prevention and monitoring for small teams
- Why calm, early alerts beat frantic firefighting
- Otterwatch: early SSL expiry alerts, free for five sites
- FAQ
- Sources
How to check your Wix site’s SSL status
Before you assume the worst, confirm what’s actually happening. A few quick checks will tell you whether you’re looking at a real expired certificate or a DNS mismatch dressed up as one.
- Open your Wix dashboard and go to Settings > Domains, then confirm HTTPS/SSL shows as connected and active for your domain.
- Load both your apex domain (example.com) and the www version in a browser, and note whether both show the warning or just one.
- Run your domain through crt.sh, a free certificate transparency log viewer, to see which certificate is actually being presented and its real expiry date.
- Check your DNS records (A, CNAME, and CAA) through your domain registrar’s control panel or a tool like
digornslookup. - If you’ve made DNS changes recently, wait 24 to 48 hours for propagation before troubleshooting further, since Wix’s own guidance notes that activation can take up to two full days.
Here’s what to have ready if the problem persists:
- The exact error text your browser shows (not a paraphrase, the actual wording).
- A screenshot or saved link from your crt.sh lookup showing the certificate’s issue and expiry dates.
- The output of a
digornslookupcheck for both your apex and www hostnames.
Platform-managed certificates, per Wix’s support documentation, remove most of the manual work, but they don’t remove the need for you to confirm your DNS is pointed correctly. That one step catches most false alarms before you ever need to open a ticket.
Common causes for a Wix SSL to show as expired
Most “expired SSL” reports on Wix sites trace back to one of a handful of repeat offenders. None of them require deep technical skill to spot, and most are fixable without waiting on support.
- Partial domain pointing. Your apex domain and www subdomain point to different places, so one gets a valid Wix certificate and the other doesn’t.
- CAA record conflicts. A Certificate Authority Authorization record at your registrar can block the certificate authority Wix uses from issuing or renewing a cert, even when everything else looks fine.
- Propagation delays. Recent DNS edits haven’t fully rolled out across the internet yet, which can take up to 48 hours.
- Stale records from mixed hosting. If you moved to Wix from another host and didn’t clean up old DNS entries, some hostnames may still point at non-Wix servers.
- Platform-side hiccups at Wix. Rare, but they happen, and they’re usually visible in community reports before Wix issues a fix.
Community troubleshooting threads on this exact topic show a consistent pattern: site owners who dig into their DNS setup find a mismatch between apex and www routing, or a CAA record they forgot they’d added years ago. In several of those reported cases, only Wix could finish resolving the issuance problem once the DNS side was corrected, because Wix controls the certificate issuance step itself.
Partial pointing is the single most common culprit. It happens when someone configures the apex domain correctly during setup but leaves the www record pointed at an old host, a parking page, or a different DNS provider entirely. Browsers checking the www version then see whatever certificate (or lack of one) lives on that other server, and report it as expired or invalid, even though your actual Wix-hosted site is fine.
CAA records are the quieter troublemaker. They exist to restrict which certificate authorities are allowed to issue certificates for your domain, which is a reasonable security measure. But if you or a previous developer added a CAA record that doesn’t include the authority Wix uses, renewal attempts can fail silently until someone notices the padlock has disappeared.
Pro Tip: Before touching any DNS settings, take a screenshot of your current A, CNAME, and CAA records. If a fix doesn’t work, you’ll want to revert cleanly instead of guessing what you changed.
If your Wix SSL is expired: a prioritized remediation checklist
Work through these steps in order. Most expired-certificate reports resolve in the first three steps without ever needing to contact support.
- Capture the exact browser error. Note the specific warning text and which hostname (apex, www, or both) triggered it.
- Test both hostname variants separately. Load
yourdomain.comandwww.yourdomain.comin separate tabs to isolate the problem. - Run a crt.sh lookup. Confirm which certificate is actually live and when it was issued and when it expires.
- Check your DNS records. Verify A, CNAME, and CAA entries at your registrar, and compare them against Wix’s documented setup requirements.
- Re-save your domain connection in Wix. Sometimes simply re-confirming the connection in your dashboard triggers a fresh certificate request.
- Wait 24 to 48 hours if you’ve made any DNS changes, since propagation delays are a frequent false alarm.
A few things to avoid while you’re troubleshooting:
- Don’t repeatedly toggle SSL on and off in your Wix dashboard. Community reports suggest this creates confusing intermediate states rather than fixing anything.
- Don’t make multiple DNS changes at once, since that makes it harder to identify which change actually helped.
- Don’t skip the propagation wait, even if you’re in a hurry; checking too early just produces more false negatives.
If none of this resolves the issue, it’s time to contact Wix support, but bring evidence instead of just a screenshot of the warning. Include your crt.sh link, the dig or nslookup output for both hostnames, a note on any DNS changes you made in the last week, and the exact browser error text. Our practical remediation guide walks through gathering this same evidence set in more detail if you want a second reference while you prepare your ticket.
Certificate lifetimes and industry changes to watch for in 2026
Certificate validity periods have been shrinking for years, and that trend is accelerating. The CAB Forum’s ballot on reducing validity and data reuse periods lays out a step-wise schedule that brings maximum certificate lifetimes down from the 398-day cap toward much shorter windows starting in 2026 and continuing in later years.
The practical effect is simple: certificates renew more often. Shorter lifetimes reduce the window of exposure if a certificate is ever mishandled or compromised, which is good for security overall. But more frequent renewal cycles also mean more opportunities for an edge-case failure, like a DNS mismatch or a CAA conflict, to interrupt the process.
This is exactly why platform-managed issuance matters, and why it isn’t a complete substitute for owner attention. Wix handling certificate issuance for you removes the manual renewal burden entirely under normal conditions. It doesn’t remove your responsibility to keep DNS records clean and consistent, because that’s the layer where almost all real-world failures originate, managed platform or not. Our renewal mechanics overview breaks down how automated renewal timing actually works if you want the fuller picture.

Prevention and monitoring for small teams
A little DNS housekeeping prevents most of the headaches covered above. None of it takes more than a few minutes once you know what to look for.
- Keep your apex and www records pointed at the same place, and recheck this after any hosting or DNS provider change.
- Remove stale DNS entries from old hosts you’ve since migrated away from.
- Only add a CAA record if you specifically need one, and if you do, confirm it includes the authority your platform actually uses.
- Document DNS changes as you make them, even a one-line note with a date, so you have a trail if something breaks later.
- Do a five-minute manual check once a month: load your site, check the padlock, glance at the certificate’s expiry date.
Pro Tip: Write down who manages your domain registrar login. A surprising number of expired-certificate panics happen because the person who can access DNS settings left the company or the project months ago.
The habits above help, but they rely on you remembering to check. That’s where automated monitoring earns its keep: a tool that watches expiry dates, flags hostname mismatches, and confirms your site is reachable catches problems days before a visitor ever sees a warning. The best version of this sends you a plain heads-up well ahead of the deadline, not a wall of red alerts after something’s already broken. If you’re also thinking about how uptime and HTTPS status affect how your site gets found and crawled, this partner guide on Wix AI visibility covers the broader search-side implications.

Why calm, early alerts beat frantic firefighting
Most monitoring tools are built for ops teams who live in dashboards all day. If you’re running a small site or a handful of client projects, you don’t need graphs, you need to know, with enough lead time to act calmly, that a certificate is coming up for renewal. That’s the whole idea behind expiry-first monitoring: fewer alarms, better timing, no dashboard required.
— Nick Phillips
Otterwatch: early SSL expiry alerts, free for five sites
We built Otterwatch around one habit: check certificates before they become emergencies, and tell you about it in plain language instead of a wall of red. We offer a free plan that watches a limited number of sites at no cost, covering expiry dates, hostname mismatches, and basic reachability, with alerts delivered by plain email instead of a complex dashboard.

- Our free tier monitors a limited number of sites with no credit card required.
- Alerts arrive by email, without requiring you to use dashboards or interpret alarms.
- Our Pro plan adds deeper certificate monitoring and change detection for $15 per month, for teams managing more than five domains.
If you just want a one-off answer right now, our free SSL certificate checker will show you exactly what certificate your domain is presenting and when it expires, no sign-up needed.
FAQ
How long will an SSL certificate be valid for in 2026?
Maximum certificate validity has been shrinking under CAB Forum rules, with a step-wise schedule reducing lifetimes below the previous 398-day cap starting in 2026. The exact window depends on the certificate authority and when the schedule’s phases take effect, so check your certificate’s own issue and expiry dates with a tool like crt.sh rather than assuming a fixed number.
Does Wix include an SSL certificate?
Yes. Wix’s own support documentation confirms that SSL protection is included at no extra cost for Wix-hosted sites and custom domains connected to Wix, so you typically don’t need to purchase or install a certificate yourself.
What should I do if an SSL certificate is expired?
First, confirm it’s a real expiration rather than a DNS mismatch by checking both your apex and www hostnames and running a crt.sh lookup. If DNS and propagation checks come up clean after waiting 24 to 48 hours, contact Wix support with your crt.sh results, DNS lookup output, and the exact browser error text.
Is it true that my SSL certificate is only valid for 6 months?
Not universally. Current certificates from major authorities have historically allowed up to 398 days, though CAB Forum proposals are phasing in shorter maximum lifetimes over the coming years. The safest way to know your own certificate’s validity window is to check its issue and expiry dates directly rather than relying on a rule of thumb.
How can I avoid getting caught off guard by SSL expiration?
Keep your DNS records clean and consistent between apex and www, and consider a monitoring tool that flags upcoming expirations before they become visible warnings. Our prevention guide covers a simple monthly check routine that catches most issues early.
Sources
- About HTTPS and SSL | Help Center
- WIX-site HTTPS certificate expired - How to fix? - Help
- Ballot: introduce schedule of reducing validity and data reuse periods
Recommended
- How to Avoid SSL Expiration Warnings: 2026 Guide
- Fix Expired SSL Certificates Quickly: A Practical Guide
- Copy Ready Certificate Expiry Calendar for Small Teams
- SSL Certificate Renewal Explained: 2026 Guide
Catch the next cert expiry before your users do.
Otterwatch checks your SSL certificates daily and emails you 30 days before they expire. Five sites free.
Start watching →