The symptom
While setting up or using your email in Outlook, Thunderbird, or on a phone, a warning appears saying something like "the server you are connected to is using a security certificate that cannot be verified," "certificate name mismatch," or "cannot verify server identity," usually with buttons offering to continue anyway or view the certificate.
Do not just click past it. The warning is not necessarily a sign of danger, but it is always a sign that something in your settings deserves a look, and clicking "continue" forever trains you to ignore the one time the warning matters.
What the warning means
When your mail program connects securely, the server presents a certificate proving its identity, and that certificate is issued for a specific server name. The warning appears when the name your mail program is connecting to does not match a name on the certificate, or the certificate has expired, or it was not issued by an authority your device trusts.
By far the most common cause on our hosting is the name mismatch: your mail program is pointed at a server name that works for delivery but is not the name on the certificate. The connection still encrypts, but your program cannot confirm it is talking to the right machine, so it asks you.
The usual causes
- The mail server name in your settings doesn't match the certificate. For example, the settings use the bare domain yourdomain.tld instead of mail.yourdomain.tld, or an old server name from a previous host is still configured.
- Your domain's mail certificate hasn't been issued yet. Certificates on our servers are issued and renewed automatically, but on a brand-new domain or right after a migration there can be a short gap before the certificate covering your mail server name exists.
- The certificate expired and hasn't renewed. Renewal is automatic, so a genuinely expired certificate is rare and worth reporting to us rather than working around.
- The date and time on your device are wrong. Certificate checking depends on the clock, a device with the wrong date can distrust perfectly valid certificates everywhere, not just for email.
- You are on a network that intercepts secure connections, some corporate networks and public hotspots do this. If the warning only appears on one network and vanishes on mobile data, the network is the cause.
How to fix it
- Check the server name first. In your account settings, confirm both incoming and outgoing servers are set to mail.yourdomain.tld exactly, as listed in our email settings and ports quick reference. Fix any variation, and the warning usually disappears with it.
- Check your device's date and time are correct and set to automatic.
- Test on a different network if the warning appeared suddenly on a connection that used to work, mobile data versus Wi-Fi is the quickest comparison.
- View the certificate details in the warning dialog if your program offers it. The names the certificate covers and its expiry date will tell you immediately whether you have a name mismatch, an expiry, or something else.
- If the settings are correct and the warning persists, open a support ticket with a screenshot of the warning and the certificate details if available, and tell us which program and device. If the certificate for your domain is missing or stuck, we reissue it from our side, this is quick and there is no workaround you should need to live with.
Good to know
Accepting the certificate permanently, which some programs offer, makes the warning go away without fixing anything, and it removes your protection against a genuine impersonation of the mail server later. Use it only if we have specifically confirmed the certificate situation with you and told you it is safe in your case. The correct end state is no warning at all: right server name, valid certificate, no exceptions stored.