Secure connection and certificate errors
NET::ERR_CERT_COMMON_NAME_INVALID
The certificate belongs to a different website name.
Quick answer
The certificate is valid, but not for the exact address you opened. For example it covers example.com but not www.example.com. The browser stops because it cannot confirm it is the right site.
When to wait: Waiting does not help.
If you are visiting the website
- Try the other variant Try the address with or without "www." in front. Many sites only have a certificate for one of the two.
- Check the spelling and the link Look at the address carefully. A link from an email or ad may point to a look-alike name. If the name looks odd, type the real address yourself instead.
- Test on mobile data or another network A Wi-Fi login page or a filtering network can answer in place of the real site, using a certificate for its own name. Taking the device off that network shows whether the network is involved.
- Windows
- Start > Settings > Network & internet > Wi-Fi. Switch to a different network or a phone hotspot and reload.
- macOS
- Use the Wi-Fi menu in the menu bar to join a different network or a phone hotspot, then reload.
- Android
- Settings > Network & internet > Internet. Turn off Wi-Fi to test on mobile data.
- iPhone and iPad (iOS)
- Settings > Wi-Fi. Turn off Wi-Fi to test on mobile data.
- Finish any Wi-Fi sign-in On hotel or café Wi-Fi, open any plain http:// address to bring up the login page. After signing in, open the site again.
- Tell the website owner If the error appears everywhere, the certificate does not list the name you opened. Contact the site through another channel and say exactly which address failed.
If you run the website
- See which names the certificate covers Run
openssl s_client -connect example.com:443 -servername example.comand pipe it intoopenssl x509 -noout -subject -ext subjectAltName. Browsers only use the Subject Alternative Name list, so the exact hostname must appear there. - Add every hostname to the certificate Include the bare domain, www and any subdomains people use. With Certbot, request them together, for example
sudo certbot --nginx -d example.com -d www.example.com, then reload. - Check the server_name and SNI setup On servers with several sites, the server picks a certificate based on SNI (the site name the browser sends). If no server block matches, a default site's certificate is sent. Make sure each server_name block has its own matching certificate.
- Check DNS points to the right server Run
dig example.com A +shortanddig www.example.com A +short. If one name still points to an old host or a shared server, it receives that server's certificate. - Redirect the uncovered name properly A redirect from www to the bare domain only works if the www name also has a valid certificate. The browser checks the certificate before it ever sees the redirect.
What the error means in plain words
The certificate is real and trusted, but it was made for a different name. It is like a valid passport that belongs to someone else.
The browser cannot tell whether the site is misconfigured or whether someone is pretending to be it. So it stops.
Why www and non-www behave differently
To a browser, example.com and www.example.com are two different names. A certificate must list each one.
Owners often forget one of them. That is why typing the other variant is the quickest test for visitors.
For developers: CN versus SAN
Older certificates put the site name in the Common Name field. Modern browsers ignore that field and only check the Subject Alternative Name list.
A wildcard such as *.example.com covers www.example.com but not example.com itself, and not deeper names like a.b.example.com.
Common questions
Is it safe to continue past the warning?
Not on a site where you log in, pay or share personal data. The browser cannot confirm you reached the real site. Use the correct address instead, or wait for the owner.
Why does example.com work but www.example.com does not?
The certificate only lists one of the two names. The owner needs to add the missing name to the certificate.
What does SSL_ERROR_BAD_CERT_DOMAIN mean in Firefox?
It is Firefox's code for the same problem. The certificate does not match the address you opened.
Can I fix this from my side?
Only if the cause is a typo, the wrong www variant or a Wi-Fi login page. If the real address fails on every network, only the site owner can fix the certificate.
Likely causes
- Common The certificate does not include the www or another subdomain. (Website side)
- Sometimes The domain points to a server hosting other sites. (Website side)
What to avoid
- Do not bypass the warning to log in or pay.
Is the website down? Check it now
One measurement point. Results explain what we saw, not a worldwide verdict.
Related messages
Sources
- Chromium source: net/base/net_error_list.h
- Google Chrome Help: Get help with common error messages in Chrome
- Mozilla Support: What do the security warning codes mean?
- OpenSSL: s_client manual
- Certbot documentation: User Guide
- Cloudflare Docs: Full (strict) encryption mode
- OpenSSL: x509 manual
Last reviewed: