“I finally got my ssl working correctly yesterday, but today I woke up with a message from the Google Search Console stating: Google has detected that the current SSL/TLS certificate used on https://www…/ does not include https://www…/ domain name. This means that your website is not perceived as secure by some browsers. As a result, many web browsers will block users accessing your site by displaying a security warning message. This is done to protect users’ browsing behavior from being intercepted by a third party, which can happen on sites that are not secure.”

Is this because when I first signed up with Cloudflare my website was not ssl enabled? For example I registered http:// instead of https:// thus when the ssl certificate is issued from Cloudflare, the certificate is for my old http:// url that I registered under? If so, is there a way that I can change my domain thats registered with Cloudflare from http-https, or must I re-register!?


Thank you!


Without seeing the details, I’m surprised Google doesn’t recognize a wildcard SSL certificate. Cloudflare’s Universal SSL certificate covers and *

So…browsers will perceive your site as being secure because is covered by *

I use Google Search Console, but I don’t use www for my domain names, so I can’t check if this is an issue for my sites. If you log into your Google Search Console, are there any warnings or errors?


Thanks for the reply this is all so confusing. No warning other then that same message in my search console inbox. The resolution says:

Recommended Action:
Update your certificate

To correct this problem, either update your current certificate to add your domain name to the list of domains protected by the certificate, or get a new SSL/TLS certificate for your domain. The certificate should be issued from a Certificate Authority (CA) that is trusted by web browsers.


Ok so perhaps this is all just a result of me not knowing how to properly use the search console, and I wasn’t supposed to add www. and https urls to the search console to being with?


I’ve had GSC “remind” me that I should add multiple combinations of http/https and www/non-www for whatever reason. My sites have one canonical URL, so I don’t do that, nor would I care to. I don’t need stats for a URL form I don’t use. So all my sites are listed as

I haven’t seen their reminder in a while. Maybe now that they’ve scanned my sites enough times, they know I just use the one format.

