What's actually wrong with your SSL certificate
An SSL certificate mismatch between Ionos and WordPress usually means one of three things: your certificate hasn't installed properly on the Ionos server, WordPress is still pointing to the old non-secure address, or the certificate has expired. The symptom is always the same — your browser shows a warning when you visit your site, or the address bar doesn't show the padlock icon.
The fix depends on which of these three is happening. Most of the time it's the second one: WordPress is configured to use http:// instead of https://, even though Ionos has a valid certificate installed. This is the easiest to fix and takes about five minutes.
Key Takeaways
- Check whether Ionos has actually installed your SSL certificate by visiting your domain in a browser and looking at the address bar — a padlock means the certificate is there.
- If the padlock appears but WordPress still shows warnings, log into WordPress and change your site URL from http:// to https:// in Settings > General.
- If there is no padlock at all, log into your Ionos control panel and verify the certificate is active under SSL Certificates, then wait up to 24 hours for it to propagate.
- Mixed content warnings (padlock with a warning triangle) mean some images or scripts are still loading over plain HTTP — use a plugin like Really Simple SSL to fix these automatically.
- If your certificate shows as expired in Ionos, renew it immediately; Ionos will not auto-renew unless you have that setting turned on.
Check whether the certificate is actually installed on Ionos
Open your browser and go to your domain. Look at the address bar. If you see a padlock icon (usually green or grey), the certificate is installed and working. If you see a warning triangle, an exclamation mark, or no padlock at all, the certificate is either not installed, expired, or not yet active.
To confirm the certificate status in Ionos, log into your Ionos control panel, find the Domains section, and click on your domain. Look for SSL Certificates or Security. You should see your certificate listed with a status of "Active" or "Valid". If it says "Pending", "Inactive", or "Expired", that's your problem — the certificate either hasn't finished installing or needs to be renewed.
If the status is Pending, wait 24 hours. Ionos can take up to a full day to activate a new certificate across their servers. If it's been longer than 24 hours and the status hasn't changed, contact Ionos support — there may be a validation issue with your domain.
Fix WordPress pointing to the wrong URL
This is the most common issue. WordPress stores your site URL in its database, and if that URL still says http:// instead of https://, WordPress will load insecure content even if Ionos has a valid certificate.
Log into your WordPress dashboard. Go to Settings > General. Look at the two fields at the top: "WordPress Address (URL)" and "Site Address (URL)". Both should start with https://, not http://. If they don't, edit them to add the "s" to http. Click Save Changes.
After you save, your site may briefly show a blank page or redirect loop. This is normal — WordPress is updating its internal links. Wait 30 seconds and refresh your browser. The padlock should now appear in the address bar.
Handle mixed content warnings
Sometimes you'll see a padlock with a warning triangle or a message saying "Not Secure" even though the main page loaded over HTTPS. This means the page itself is secure, but some images, stylesheets, or scripts are still loading over plain HTTP. Browsers flag this as a security risk because those resources could be intercepted.
The fastest fix is to install the Really Simple SSL plugin. Go to Plugins > Add New in WordPress, search for "Really Simple SSL", install it, and activate it. The plugin automatically rewrites all your internal links from HTTP to HTTPS. In most cases, mixed content warnings disappear immediately after activation.
If mixed content persists after Really Simple SSL is active, the problem is usually external resources — embedded videos, fonts from Google, or tracking scripts from third parties. Check your theme settings and any plugins that add custom code. Look for URLs that start with http:// and change them to https:// if the external service supports it.
Renew an expired certificate
If your certificate shows as Expired in the Ionos control panel, you need to renew it. Log into Ionos, go to your domain's SSL Certificates section, and look for a Renew button next to the expired certificate. Click it and follow the prompts. Ionos will usually offer to renew for another year at a set price.
After renewal, the new certificate takes up to 24 hours to activate. During this time, your site may show security warnings. This is temporary. Once the new certificate is active, the warnings will clear.
To avoid this in the future, check whether Ionos has auto-renewal turned on for your certificate. In the SSL Certificates section, look for an option to enable automatic renewal. If it's available and not already on, turn it on. This ensures your certificate renews automatically before it expires.
Force HTTPS for all traffic
Even after your certificate is installed and WordPress is pointing to the right URL, visitors might still land on the insecure version if they type http:// into the address bar. You can force all traffic to HTTPS by adding a redirect rule.
The easiest way is through WordPress. Install the Really Simple SSL plugin (mentioned above) — it includes a setting to force HTTPS for all traffic. Activate it and the plugin handles the redirect automatically.
If you prefer not to use a plugin, you can add the redirect manually. Log into your Ionos control panel, find the .htaccess file in your website's file manager, and add these lines at the very top:
RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Save the file. From now on, any visitor who tries to reach your site over HTTP will be automatically redirected to HTTPS.
Troubleshoot if nothing works
If you've checked all of the above and your site still shows security warnings, the problem is usually one of these: the certificate is for a different domain, your domain's DNS is pointing to the wrong server, or there's a caching issue.
First, verify the certificate is for the right domain. In Ionos, click on the certificate and check the "Common Name" or "Domain" field. It should match your domain exactly. If it says www.example.com but your site is example.com (or vice versa), you need a certificate that covers both — ask Ionos to issue a wildcard certificate or a multi-domain certificate.
Second, check your DNS. In Ionos, go to DNS Settings for your domain and verify the A record points to Ionos's IP address. If it points somewhere else, your domain is not actually using Ionos's servers, and Ionos's certificate won't help. Update the A record to point to Ionos.
Third, clear your browser cache. Old cached versions of your site may still show warnings even after you've fixed everything. Open your browser's developer tools (F12 on Windows, Cmd+Option+I on Mac), right-click the refresh button, and select "Empty Cache and Hard Refresh".
Frequently Asked Questions
How long does it take for an SSL certificate to work after Ionos installs it?
Usually 15 minutes to 2 hours, but Ionos says up to 24 hours. If it's been more than 24 hours and you still see warnings, contact Ionos support — there may be a validation issue.
Can I use a free SSL certificate from Ionos?
Yes. Ionos includes a free Let's Encrypt certificate with most hosting plans. It works exactly the same as a paid certificate and renews automatically. Check your Ionos control panel under SSL Certificates to see if one is already included.
What does "certificate not trusted" mean?
It usually means the certificate is for a different domain than the one you're visiting. Check that your certificate's domain matches your actual domain in Ionos. If you have both example.com and www.example.com, you need a certificate that covers both.
Will changing the URL in WordPress break my site?
It may cause a brief redirect loop or blank page, but it won't break anything permanently. WordPress will update its internal links automatically. Wait 30 seconds and refresh your browser.
Do I need to reinstall WordPress after fixing the SSL certificate?
No. Changing the URL in WordPress settings does not require reinstalling. Just update the two URL fields in Settings > General and save.