SSL and domain expiry: the boring disasters
A lapsed SSL certificate or domain registration takes the whole site out of business, not the rankings. How each one fails, why neither shows in the traffic until it is too late, and what to watch.
A lapsed SSL certificate or domain registration takes the whole site out of business, not the rankings: the browser and the crawler cannot reach the page at all. Both fail silently until the day they become catastrophic. There is no gradual ranking loss to warn you, just a day when the page stops working.
What actually happens to traffic when a certificate lapses?
When the certificate expires, browsers show a security warning and most visitors leave rather than continue. Googlebot sees a broken connection and cannot crawl the page, so the site’s crawl and render fail, and pages can be dropped from the index for the duration.
Recovery is not instant. Renewing the certificate brings the page back, but Google still has to crawl it again and re-enter the URLs on its own schedule. The traffic does not snap back the moment the certificate is valid.
What happens when the domain itself lapses?
The domain stops resolving entirely. The site, the email, and every subdomain are gone at once, because nothing points them anywhere. This is the end of the site as a reachable thing.
Recovery depends on the registrar and the TLD’s grace windows, which vary. After the window closes, the domain can be registered by someone else, and you cannot get it back through normal means. Do not treat an expiring domain as a renewal to do later; treat it as the thing that ends the business.
Why do both stay invisible until it is too late?
An expiry date is not part of the traffic. Nothing in the analytics or the rankings signals it until a visitor or a crawler hits the failure. There is no gradual page load failure beforehand, because the certificate and the domain are valid until they are not. The site looks fine right up until the day it stops loading.
What are the typical ways renewal fails?
The common ways renewal fails are easy to list and easy to have happen:
- Auto-renew turned off, or never switched on in the first place.
- The card on file expired, and the charge was declined.
- The registrar’s renewal notices go to a mailbox nobody reads.
- DNS moved to another provider, so the registrar’s renewals go somewhere stale.
- The person who owned the renewal left the company.
None of these shows up in Search Console. They all just quietly line up a day where the site stops working.
What should I watch?
Watch the certificate’s remaining days on your pages. The indexability checker shows the certificate days left for a checked URL, so it doubles as a lightweight certificate check. Watch the domain’s expiry date in your registrar or a whois lookup.
There is no dedicated SSL or domain expiry tool here yet; see the tools page for what exists. Check the certificate directly on the pages that matter, and check the domain expiry in the registrar yourself. Both are the kind of failure that monitoring can catch the day the certificate turns over, which is what stillindexed.com is for.
A certificate lapses at 2am and the whole site is down by 3am. stillindexed.com checks your pages’ certificates and directives and alerts you when something changes. Starter checks every 30 minutes, Agency every 15: https://app.stillindexed.com/auth/request