Every site gets a free SSL certificate automatically, but two things can cause the “Not Secure” warning:
- The certificate hasn’t issued yet. SSL is issued automatically once your domain points to us correctly — this can take a few hours after setup. Give it time, then reload.
- Mixed content. If your pages still link to images or scripts using http://, the padlock breaks. Update those links to https:// (in WordPress, a plugin can do this in one click).
If the site is not secure a day after setup, let us know and we will re-issue the certificate.