How to fix ssl error on BigCommerce

Replace or reissue your SSL/TLS certificate so it is valid for the exact domain name your store uses, eliminating the hostname mismatch error.

Steps for BigCommerce

  1. BigCommerce automatically provisions SSL for your store's default domain (*.mybigcommerce.com) and for custom domains connected through their system.
  2. Go to: BigCommerce Admin → Store Setup → Domain.
  3. If your custom domain has an SSL issue, verify that your DNS CNAME record points to your BigCommerce store URL (shown in the Domain settings page).
  4. Remove the custom domain and re-add it to trigger a fresh certificate provisioning if the mismatch persists.
  5. For multi-storefront setups, each domain must be added separately and have its own DNS record pointing to BigCommerce.
  6. Contact BigCommerce Support if automatic provisioning fails after DNS is confirmed correct.
Official BigCommerce documentation ↗

What is ssl error?

Every HTTPS website uses an SSL/TLS certificate to prove its identity to browsers and to encrypt the connection. The certificate must explicitly list the domain name (or names) it is allowed to protect. A "hostname mismatch" error means the certificate installed on your server was issued for a different domain than the one visitors are actually trying to reach — for example, the certificate covers "www.yourstore.com" but not "yourstore.com" (or vice versa), or it was issued for a completely different domain altogether. Browsers and security scanners treat this as a critical failure and refuse to establish a trusted connection.

When a hostname mismatch exists, most modern browsers display a full-page "Your connection is not private" warning before visitors can even see your store. This kills conversions — the majority of shoppers will leave immediately rather than click through a security warning. Google also uses HTTPS as a ranking signal and can demote or omit pages it cannot crawl securely. Beyond lost sales and rankings, transmitting payment and personal data over an untrusted connection is a serious security risk and may violate PCI DSS compliance requirements for accepting card payments. This maps directly to OWASP A02:2021 — Cryptographic Failures.

See the complete Ssl error guide for every platform and the full background.

Not sure if your BigCommerce store has this?

Run a free SEOLZ audit — we’ll find ssl error and every other issue across your whole site.

Scan my site free

Fix ssl error on another platform