Find out whether Chrome is showing a warning on your site
If your address starts with http, Chrome writes "Not secure" beside it. If your enquiry form collects names and phone numbers, that data is travelling in the clear.
No signup, no payment · about 30 seconds · reads only public pages
Figures from our own scans, September 2026 · built while checking 940-odd manufacturer websites
The first thing a new visitor reads is a warning
Chrome marks any page served over http as "Not secure". You did nothing wrong. The browser writes it anyway, and it sits in the address bar above everything you do.
Position is the problem. Someone who found you through a search sees the address bar before they see a single product. They are reading a warning before they know what you make. A long-standing customer shrugs and carries on. A first-time visitor sometimes does not.
Some corporate networks go further and block the page outright. That happens in defence, in public-sector supply chains and in larger primes. The person on the other end does not conclude that your certificate has lapsed. They conclude that your website is down, and they move on.
Then there is the form. If you collect names, phone numbers or drawings, all of it crosses the network unencrypted. Where any of those visitors are in the UK or the EU, that is a data protection question as much as a technical one.
Look at the address bar
- Open the site and read the left end of the address bar. "Not secure" means no certificate is in play.
- Check whether the address begins http or https.
- Type the https version directly. A full-page warning means the certificate has expired or does not match the name.
- Try it with and without www. The two are often configured differently.
That last one catches people out. It is common for the www version to be fine while the bare domain throws a warning — which means only the people who typed the address off your business card ever see it. That is precisely the group least likely to tell you.
Usually just the certificate
This is not a rebuild. Ask your host to install a certificate and it is generally done in a day or two. A free certificate is fine.
The part people skip is the clean-up afterwards: making every internal link and image load over https too. Miss that and the warning persists even though the certificate is installed. Whoever maintains your site can do all of this, and the result says so — this is one you do not need me for.
The person behind the tool
About this check
Are free certificates any good?
Yes. Most hosts issue and renew them automatically, and browsers treat them exactly the same as paid ones.
Will HTTPS improve my search ranking?
Nobody can promise you a ranking. Google has said for years that it is one signal among many. The stronger argument is the warning your visitors currently see.
We have lost contact with whoever built the site.
Then the first question is whose name the domain and hosting are in. Until that is untangled, nobody can install anything. Send the result over and I will tell you where to start.
Want to see yours rebuilt first
I will build a concept of your homepage using your own name and your own products, so you can see what these findings look like once they are fixed. The concept is free — if you do not like it, close the tab.
Get a free conceptCompany name and URL is all it takes · nothing owed at the concept stage