Guide
Why an SSL certificate works for one domain but not another
Check www, subdomains, redirects, and certificate names before a browser warning reaches visitors.
Start with the essential
A valid certificate is not automatically valid for every version of a site address. For example, a certificate for example.com may not cover www.example.com, shop.example.com, or a temporary staging hostname. A visitor who reaches an uncovered address can still see a certificate warning even though the main site looks fine.
Put it into practice
List the public hostnames people can actually open: the root domain, www, checkout or app subdomains, and any domain used in marketing links. Check each hostname separately, then compare it with the names listed on the certificate. A redirect does not solve the problem if the browser must establish a secure connection before following that redirect.
A detail worth checking
Pay particular attention after moving a domain to a CDN, changing hosting providers, or adding a subdomain. DNS may point to the new service while the new certificate has not finished issuing, or an older load balancer may still answer some requests. Test the final public hostname rather than only the hosting dashboard.
Your next step
Use the SSL Certificate Checker as a quick hostname-by-hostname review, then open the same addresses in a browser before a campaign or release. This catches a small configuration gap before it becomes a trust problem for visitors.
Use this as a small, repeatable check rather than a one-time task.