Skip to main content

SSL expiry and Merchant Center: how to stop it lapsing

An expired SSL certificate puts a browser warning in front of every page of your store, and Google’s checkout rules ask for a valid certificate. Watch the expiry date yourself, renew early, and re-test checkout after every renewal. It is almost always a renewal that was meant to be automatic and quietly wasn’t.

Critical5 min read

Why this matters

Google's “Checkout requirements and best practices” page leaves no room for doubt: “you must secure your checkout with a valid SSL certificate”. Its Shopping ads policy on irresponsible data collection gives, as an example of what is not allowed, taking names, addresses or card numbers “over an unsecured page which is not SSL protected and without a valid certificate”. An expired certificate is not a valid one. The day it lapses, a checkout that met the rule yesterday stops meeting it, and nothing on your site changed.

The landing page rules point the same way. Google's “About landing page requirements” page asks you to “Make sure your landing page is live, and that it isn’t under construction or displaying an error, like a 404 error.” A full-screen browser warning is not the product page a shopper clicked for. Google's page on landing page maintenance spells out what carrying on costs: “If your product data remains active when your landing page isn't, you could end up paying for clicks when customers visit your landing page's error message.”

Certificates do not fail loudly. Most hosts and platforms renew them automatically, which is exactly why a lapse catches people out: the card on file expired, a DNS change broke the renewal's validation check, or the renewal covered www and forgot the bare domain. A certificate does not renew itself just because a dashboard says auto-renew is on. The cure is dull and reliable: a second reminder that does not depend on the renewal system, and a real look at the new expiry date after each renewal.

If it has already lapsed, renew first, then check the padlock on the homepage, a product page, the cart and each checkout step. Google's “How to fix: Landing page not working” page says “If your landing page is not working, pause your item until your site is fully functioning.” For planned work, such as moving host or certificate provider, its maintenance page adds: “If you use automatic item updates, disable them at least 24 hours before your landing page becomes unavailable.”

The free scan opens your store over HTTPS the way a shopper's browser does. It reports a certificate that fails verification as a failure and flags a checkout page that is not served over HTTPS, so a lapse shows up on your screen before a customer emails about it. For the full security picture read SSL and HTTPS for Merchant Center, and see the list of security checks on the misrepresentation checker.

Typical evidence

A dated document, and the date is a cliff

A certificate expiry can turn a working page into a browser security warning immediately. Monitor the date and renew early; a public scan cannot predict how any platform will respond.

issued14-day warnexpired · now
Valid until
12 Jun 2026
EXPIRED 2 days ago
Independent expiry monitor → alerts at 30 / 14 / 7 days. Don't let the thing that renews the cert be the only thing watching it.
A lapse can make the storefront unusable until someone notices. Monitoring shortens that outage; do not infer listing or account consequences from the downtime alone.

The public signals this check looks for:

  1. Automatic renewal failed without telling anyone…

    Automatic renewal failed without telling anyone: a declined card, a DNS change that broke the validation check, or a renewal job that stopped after a server move.

  2. The renewal reminders went to a founder’s old address, a shared inbox nobody reads, or the…

    The renewal reminders went to a founder’s old address, a shared inbox nobody reads, or the agency that built the site and has since moved on.

  3. Only one hostname was renewed…

    Only one hostname was renewed: www loads cleanly and the bare domain shows a warning, or the other way round.

  4. A certificate covering several brands or subdomains dropped one of them during a migration…

    A certificate covering several brands or subdomains dropped one of them during a migration, often the shop or checkout subdomain.

  5. The store moved host or CDN, and the old certificate kept serving on one address until it …

    The store moved host or CDN, and the old certificate kept serving on one address until it ran out.

What it looks like once it is right

A free SSL monitor emails two staff a month and a week before expiry. After each renewal someone clicks the padlock, notes the new date, and walks through to the payment step on the bare domain and on www.

Common mistakes

Common mistake

The card behind the certificate renewal expires in March. The warning emails go to an agency inbox nobody checks, and on renewal day every page shows “Your connection is not private” while the Shopping ads keep sending paid clicks to it.

Fix checklist

Automation fails quietly — this is how

Renewal is delegated to a cron job, a billing card and an inbox, and any one of them can rot without a sound. The only line in this log that would have saved the store is the one that isn't there: an independent monitor watching the date.

cert-renew · event loglapsed
−30 daysauto-renewal scheduled
−2 daysrenewal attempt → billing card declined (expired)
−2 daysnotice sent to founder@old-inbox — unread
00:00certificate expired · every page now serves a security wall
+2 dayscustomer emails 'your site looks hacked'
Put an external monitor on expiry (alerts at 30/14/7 days) to a channel people actually read, and add two or three real humans to the provider's notification list.

Questions merchants ask

What happens to my Google Shopping listings if my SSL certificate expires?

Your checkout stops meeting Google's requirement for a valid SSL certificate, and shoppers get a browser warning in place of your page. Google's landing page help asks for pages that are live and not showing an error, and suggests pausing items until the site works. Renew, re-test the checkout, then request a review if Merchant Center shows an issue.

Is a free SSL certificate good enough for Merchant Center?

Google's checkout requirements ask for a valid SSL certificate; they name no brand and no paid tier. A free certificate that is valid, covers every hostname you use and renews on time does the job. The price of the certificate matters far less than the date on it.

How do I check when my SSL certificate expires?

Click the padlock in the browser address bar on your store and open the certificate details: the expiry date and the hostnames it covers are listed there. Check the bare domain and www separately, then set a reminder outside the system that renews it. The free scan also reports a certificate that fails verification.

Remediation

Risk signal

An expired certificate is the cheapest outage to prevent and one of the most annoying to explain: nothing on the site changed, yet every shopper meets a warning page. Watch the date yourself, check each renewal by hand, and run a scan after any move of host or domain.
PriorityTreat this and any other highest-severity findings as first-priority work, then document each fix.
EvidenceRecord the current state before each change, apply the fix, then capture the corrected state so every change is evidenced.

Similar cases

Sources

  1. Checkout requirements and best practicesGoogle Merchant Center Help — support.google.com
  2. Irresponsible data collection & use (Shopping ads policy)Google Merchant Center Help — support.google.com
  3. Best practices for landing page maintenance or a planned site outageGoogle Merchant Center Help — support.google.com

Last reviewed 23 Sep 2026.

That is one issue. The library documents 134.

The free scan lists what it finds on your store. The paid report adds the affected pages, captured evidence and step-by-step fixes. Start free, with no account needed.