SSL certificates have expiry dates. When that date passes and the cert isn't renewed, something very visible happens: every browser blocks access to the site with a full-screen security warning. For agencies managing client websites, this is one of the most avoidable — and most embarrassing — failures that can happen.
Here's exactly what occurs, who sees what, and why the agency almost always gets blamed.
What users see immediately
The moment an SSL certificate expires, browsers detect it on the next connection attempt. Chrome shows "Your connection is not private" with a red warning triangle. Firefox shows "Warning: Potential Security Risk Ahead." Safari blocks the page entirely with a red address bar.
Most users don't know what an SSL cert is — they just see a warning that says the site is dangerous. The vast majority click away immediately. A study by GlobalSign found that 84% of users would abandon a purchase if they saw a browser security warning.
What happens to traffic and revenue
Traffic drops to near zero within minutes of cert expiry. Search engines also notice: Googlebot will encounter the security error, and the site may be temporarily de-ranked or flagged. For e-commerce clients, every minute of downtime has a direct revenue cost.
For a site doing $10,000/day in revenue, a 4-hour cert expiry during business hours costs $1,667 in lost sales — before counting support costs, client calls, and relationship damage.
Why the agency gets blamed
From the client's perspective, the agency manages the website. When the website breaks, the agency failed. It doesn't matter that the cert was managed by the client's registrar account from 2019, or that the renewal email went to a mailbox nobody checks.
The client's business was disrupted. Their customers saw a scary warning. Their site was effectively down. The agency is the technical partner — this is their job to prevent.
The most common causes of cert expiry
- Renewal emails go unread: Registrars send reminders 30, 15, and 7 days out — but to whatever email was used when the cert was purchased, often years ago.
- Auto-renewal fails silently: Credit cards expire, billing accounts change, and auto-renewal breaks without any visible alert.
- Let's Encrypt renewal scripts fail: Certbot and similar tools can break after server updates, and the failure isn't obvious until the cert expires.
- Cert ownership is fragmented: Different clients use different registrars, hosts, and CDNs. There's no single place to track all of them.
How long does it take to fix?
If you have access to the right account and know exactly what to do, renewing a cert takes 5–15 minutes. But in practice:
- Finding which account controls the cert: 10–30 minutes
- Getting login credentials: 10–60 minutes
- Renewal and propagation: 5–30 minutes
- Verifying and clearing caches: 5–15 minutes
A routine renewal that should take 10 minutes often takes 1–2 hours under emergency conditions, especially when clients are calling while you're trying to fix it.
How to prevent it
The answer is monitoring — not calendar reminders, not spreadsheets, not hoping that auto-renewal works. Automated monitoring checks every cert continuously and alerts you well before expiry.
For agencies, the best setup is:
- Monitor every domain, every client, from one dashboard
- Get alerted at 30 days — plenty of time for a planned renewal
- Get alerted again at 7 days — in case the 30-day alert was missed or renewal failed
- Keep the renewal process documented so any team member can handle it
Vizze does all of this automatically. Add your clients and their domains, and every cert expiry is tracked with alerts routed to the right people — before the client ever notices a problem.