The SSL certificate is what makes the browser show the padlock and the address start with https://. Without it, Chrome marks the site as "Not secure" right next to the address โ and Google uses HTTPS as a ranking signal. At RedHosting the certificate is free on every hosting plan.
The hosting issues the certificate on its own, through AutoSSL, as soon as the domain starts pointing to the server. Before anything else, check:
If everything is green, skip to step 3.
If any domain shows up without a certificate:
An issued certificate doesn't redirect by itself: the site keeps opening over http:// for anyone who types it that way. cPanel fixes this with one toggle:
If you'd rather do it in .htaccess, at the top of the file in public_html:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
The certificate is valid, but the browser shows the padlock with a warning. That's mixed content: the page opened over HTTPS and is loading some image, CSS or script over HTTP.
To find the culprit, open the page, press F12 and check the Console tab โ the browser lists every insecure resource.
On a WordPress site, the fix is usually:
https://.http://yourdomain for https://yourdomain in the database. Old addresses stay stored in posts and don't change by themselves.On a hand-built site, search for http:// in the HTML and CSS and replace it with a relative path โ /images/photo.png instead of the full address.
AutoSSL renews on its own before expiry, with nothing for you to do. Renewal only fails if the domain stops pointing to the hosting โ in that case cPanel warns you by email.
https:// version.http://.mail.yourdomain.com โ it's worth reconfiguring your phone to use SSL/TLS.Open a ticket at financeiro.redhosting.com.br or contact support on WhatsApp at +55 11 98833-3902.