Certificate doesn't cover this hostname

Check id: tls.hostname_mismatch · fix effort: medium

What it means

Your certificate was issued for different names, so browsers warn visitors that the connection isn't trusted.

The technical detail

The leaf's SANs don't cover the connecting hostname. Common causes are a shared-hosting default cert or a cert covering only www.

How to fix it

  1. Reissue the certificate covering both apex and www (or use a wildcard).
  2. On shared/CDN hosting, attach the hostname so the right cert is served via SNI.

Does your domain have this problem?

Run a free scan, takes about ten seconds.