Fixing "Not secure" and SSL errors on Wix

By: Irina Shvaya | October 5, 2026
This guide is part of our Wix resource hub: whether Wix fits, what it costs, SEO and speed, security, and guides for moving to or away from Wix.

A Wix site shows "Not secure" for one main reason: the SSL certificate for your domain hasn't been issued yet, and it hasn't been issued because the domain's DNS records are incomplete or still propagating. Wix creates the certificate automatically, but only once the domain is fully connected. Fix the records, wait up to 48 hours, and the warning clears without any further action from you.

There is no SSL switch to turn on in Wix and no certificate to buy. That is useful to know, because it means the fix is never inside an SSL settings page. It is in your DNS records, at your domain host, or in a piece of embedded code on the page.

The steps below follow Wix's own troubleshooting order, then cover the cases that look like SSL problems but aren't.

Key Takeaways

  • Wix provides an SSL certificate automatically for every site at no additional cost, and HTTPS cannot be manually disabled.
  • The certificate is generated within 48 hours of updating your DNS records, and only after propagation is complete.
  • A domain connected by pointing needs both an A record (185.230.63.107) and a www CNAME (pointing.wixdns.net). Updating only one is a documented cause of the "Not secure" warning.
  • DNSSEC at your domain host and CAA records on a pointed domain can both block the certificate.
  • An HTML embed that contains http:// code can make the browser report a page as not fully secure.
  • Wix does not support third-party SSL certificates, and a red "dangerous site" screen is a different problem from SSL.

How SSL works on Wix

SSL (more precisely TLS, its modern version) encrypts the connection between a visitor's browser and your site. A site with a valid certificate loads at an https:// address and shows a padlock or similar icon. A site without one gets a "Not secure" label in the address bar, and some browsers show a full-page warning first.

On Wix, the process is automatic. Wix says: "We provide an SSL certificate automatically for all sites created on Wix at no additional cost." HTTPS is switched on by default and can't be turned off. A certificate is generated for each custom domain and subdomain you connect. Wix's SEO learning hub also says that Wix redirects http addresses to https automatically, so you don't need to set that up.

The certificate depends on the domain connection. Wix's wording is that it is "automatically generated within 48 hours of updating your DNS records", and separately that it "will only be issued once propagation is complete". Propagation is the period, up to 48 hours, in which a DNS change spreads across the internet. So a brand-new connection that shows "Not secure" on day one is behaving normally.

Step 1: check the DNS records for your connection method

A domain reaches Wix in one of two ways, and the records to check differ.

Connection methodWhere the records areWhat to check
PointingAt your domain hostA record: host @ (or blank), value 185.230.63.107. CNAME record: host www, value pointing.wixdns.net
Name servers, or a domain bought from WixIn your Wix accountThe default A and CNAME records under Domains → Domain Actions → Manage DNS Records

For pointed domains, the classic mistake is updating the A record and forgetting the CNAME, or the reverse. Wix is direct about the result: "If you do not update both records, your site will not appear secure and your visitors may see a 'Not secure' warning message." A typical symptom is that yourdomain.com is secure and www.yourdomain.com is not, or the other way around.

Also look for leftovers. An extra A record still pointing to a former host sends some visitors to a server that has no certificate for your Wix site. Delete it.

For domains on Wix name servers, the records normally take care of themselves. If someone has edited them, restore the defaults using the values Wix shows in your account. Our guide to a Wix domain that won't connect goes through both methods record by record.

Step 2: wait the full 48 hours

Wix's second step is simply to "wait up to 48 hours to allow your domain to complete propagation." Count from your most recent DNS change, not from the day you first connected the domain. If you corrected a record this morning, the clock started this morning.

While you wait:

  • Test in a private or incognito window, so an old cached warning doesn't mislead you.
  • Test both versions of the address, with and without www.
  • Try a second network, such as your phone on mobile data. During propagation a site can be secure on one network and not on another.
  • Avoid changing the records again unless you find an actual error.

Wix does not document a button for re-issuing a certificate by hand. The documented route is correct records plus time.

Step 3: make sure DNSSEC is not signed

DNSSEC is a feature at domain hosts that digitally signs DNS records to prevent tampering. For a domain bought somewhere other than Wix, Wix says to check with your domain host "to make sure that DNSSEC is not signed for your domain as it can interrupt the propagation process." If propagation can't complete, the certificate is never issued.

Look for a DNSSEC setting in your domain host's control panel, or ask their support to confirm it is off. This step doesn't apply to domains purchased from Wix.

The same goes for DNS proxies. Wix states that it does not support DNS proxies like Cloudflare. If your DNS runs through one, the proxy needs to be off for the records that send traffic to Wix.

Step 4: remove CAA records on a pointed domain

A CAA record (Certification Authority Authorization) is a DNS record that lists which certificate providers are allowed to issue certificates for your domain. IT teams sometimes add them on purpose as a security measure.

On Wix they get in the way. Wix's page on CAA records says: "Currently, CAA records are not supported by Wix. If you have connected via pointing method, please make sure to remove the existing CAA record at your domain host's side." Check your DNS zone for any record of type CAA and delete it, then allow time for the change to propagate.

If your organization requires CAA records as policy, raise that with whoever sets the policy before you delete anything. It is a real trade-off of hosting on Wix. We cover other platform constraints in Wix's technical SEO limits.

Step 5: fix http code inside HTML embeds

If the certificate is fine but a specific page still shows a warning, the cause is usually mixed content. That means a secure page is loading something, such as a script, widget or iframe, from an insecure http:// address. Browsers respond by blocking the item or marking the page as not fully secure.

Wix's troubleshooting points to one place to look: code that you or a previous designer pasted into an HTML embed element. Wix's instruction is to "make sure the code you enter contains HTTPS (and not HTTP)". To fix it:

  1. Open the page in the editor and click the HTML embed element.
  2. Click Edit Code.
  3. Find every address that starts with http:// and change it to https://.
  4. Publish the site.
  5. Reload the live page in a private window and check the address bar.

If the embedded service doesn't offer an https address at all, the https version will fail to load. In that case the widget has to be replaced with one that supports https.

Remember that an edit only reaches visitors after you publish. If the warning persists after a fix, see published changes not showing on your Wix site.

Warnings that look like SSL problems but aren't

A red "dangerous site" or "deceptive site" screen

A full-page red warning is not about your certificate. Wix explains that it means Google Safe Browsing has flagged the domain for malware or phishing, sometimes because of what a previous owner of the domain did with it. The fix is to check the Security Issues report in Google Search Console, deal with anything listed, and request a review. Wix describes the process in its article on resolving a security warning for a domain. If you haven't set up Search Console yet, start with connecting Wix to Google Search Console.

A warning on one old computer only

Wix notes that devices running Windows 7 or earlier, or macOS El Capitan or earlier, may not recognize the certificate. That is a limitation of the old operating system, not a fault on your site. If every modern device shows the padlock, your site is fine.

A warning on the free Wix address or a different domain

Make sure you are testing the right address. Wix issues certificates for domains connected to Wix sites. It does not provide SSL for a domain or subdomain that points to a non-Wix site. If shop.yourdomain.com lives on another platform, its certificate is that platform's job.

An email client warning

Wix states that the Wix SSL certificate cannot be used for business email. Certificate errors in your mail app are a matter for your email provider's settings.

What you can't do with SSL on Wix

A few requests come up often enough to answer directly, as of October 2026:

  • Install your own certificate. Wix says third-party SSL certificates are not supported, and it cannot generate a CSR file (the request file a certificate provider asks for). If a compliance requirement names a specific certificate type, check that with Wix before you commit to the platform.
  • Turn HTTPS off. It is enabled automatically and can't be disabled.
  • Keep CAA records or DNSSEC on a domain connected from another host. Both have to be off for the connection to work.
  • Put a DNS proxy in front of the site. Not supported.

For most small and midsize business sites none of this matters, because the automatic certificate does the job. It matters when an IT or security policy sets rules about certificates and DNS. In that case, compare those rules with Wix's SSL and HTTPS overview before launch.

A five-minute checklist

  1. Is the site upgraded, with the domain connected? A custom domain needs an upgraded plan.
  2. Has it been 48 hours since the last DNS change?
  3. Pointing: are both the A record and the www CNAME set to Wix's values, with no stray duplicates?
  4. Is DNSSEC off at the domain host, with no DNS proxy in front?
  5. Are there any CAA records? Remove them.
  6. Does the warning appear on one page only? Check HTML embeds for http:// addresses.
  7. Is the warning red and full-page? Check Search Console for security issues.

The Wix SSL troubleshooting article covers the DNS record, waiting, DNSSEC and HTML embed steps, and the Wix Domain Assistant will confirm whether the certificate has been issued.

Conclusion

SSL on Wix is automatic, so a "Not secure" warning nearly always points back to the domain: a missing record, a setting at the domain host such as DNSSEC or a CAA record, or simply a connection that is less than 48 hours old. When the certificate is in place and one page still complains, look for http:// code in an embed. If you would rather have someone check the DNS, embeds and security settings together, our Wix website services cover that, and our Wix security guide lists the other protections worth setting up. More guides are in our Wix hub.

Frequently asked questions

Does Wix include a free SSL certificate?

Yes. Wix says it provides an SSL certificate automatically for all sites created on Wix at no additional cost. Connecting your own domain requires an upgraded plan, and the certificate for that domain is issued after the connection completes.

How long does it take for SSL to activate on Wix?

Wix says the certificate is automatically generated within 48 hours of updating your DNS records, once propagation is complete. If you edit the records again, allow another 48 hours from that change.

Why is my Wix site secure without www but not with it?

On a pointed domain, that usually means only one of the two required records is correct. The A record handles the address without www, and the CNAME handles www. Set both to Wix's values at your domain host.

Can I use my own SSL certificate on Wix?

No. Wix states that third-party SSL certificates are not supported and that it cannot generate CSR files. The automatic Wix certificate is the only option.

Is "Not secure" bad for my business?

It discourages visitors from filling in forms or buying, because the browser is telling them the connection isn't protected. Treat it as urgent, but it is usually a quick fix once the DNS records are right.

Put this into action with eSEOspace

We help businesses grow with website design that actually performs. Explore the services behind this guide:

Book a free strategy call →

Get a FREE Audit

We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.

Don't have a site yet? Get in touch →

Get a FREE GEO/AEO/SEO Audit

We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.

Don't have a site yet? Get in touch →

You Might Also like to Read