WordPress on cPanel

cPanel certificate expired: AutoSSL renewal

cPanel's AutoSSL installs and renews certificates nightly for WordPress sites. The mechanism, the CAA preflight, and how to force a check.

cPanel AutoSSL checks and renews WordPress site certificates nightly, but CAA restrictions, redirects that break HTTP validation, or DNS pointing elsewhere can block it. Open "SSL/TLS Status," inspect the pending queue and logs, correct the reported blocker, run the documented AutoSSL check manually, then verify the live certificate.

Why WordPress on cPanel does this

WordPress itself ships no certificate; on a cPanel host the certificate belongs to the web server and is managed by AutoSSL: "This interface allows you to manage the AutoSSL feature, which automatically installs domain-validated SSL certificates for the following services for users' domains". Renewal timing: "The system runs the AutoSSL feature for all users at the following times: When it performs nightly system updates via the /usr/local/cpanel/scripts/upcp script". By default "the system uses the Let's Encrypt provider", whose "default certificates are valid for 90 days". Two documented renewal blockers: the CAA preflight, "This check adds a Certificate Authority Authentication (CAA) record in the domain's zone file before AutoSSL orders a new certificate for that domain", and the provider table's scored limits, "Maximum Number of Redirects" and "Rate Limit".

Check it right now

Before changing anything, confirm what a crawler actually sees. The check is free, takes one URL and needs no account.

Run the check

How to fix it

  1. Log in to cPanel and open the SSL/TLS Status interface to see each domain's certificate expiry.
  2. Ask the host to check the Pending Queue and Logs in WHM's Manage AutoSSL interface; logs are kept for 30 days.
  3. Fix the documented blockers: CAA records that exclude the provider, redirect chains that break HTTP DCV, and DNS that does not point at the server.
  4. The host can run the check manually with /usr/local/cpanel/bin/autossl_check --all.
  5. Re-check the certificate expiry with the free SSL and domain checker below.

Why it happens again

AutoSSL renews on the server's nightly cycle, so a failure repeats nightly until the DNS or CAA problem is fixed, then resumes without ceremony. The failure is silent to the site owner: the host sees the log, the visitor sees the browser warning, and WordPress itself has no setting involved. An expired certificate on shared hosting is a host conversation, not a WordPress one.

stillindexed re-checks the URLs you give it every 30 minutes on Starter and alerts when a directive changes, at most 30 minutes after it does. It is a monitor rather than a crawler: it watches a list you choose and tells you when one of seven things changes. Card first, no trial, and a 30 day refund.

See what monitoring covers

Catching it next time

Fixing it once is the easy half. The setting that caused this can be changed again by anyone with access, and the page will keep returning 200 while it happens.

An expired or expiring TLS certificate, on other platforms

Sources

Every claim about WordPress on cPanel above is from their own documentation, read on 2026-08-30. Platforms change their settings; if one of these is out of date, their page wins and we would like to know.