The certificate does not cover the hostname being visited.
WHAT IT MEANS
The browser asked for one name; the certificate covers a different one.
COMMON CAUSES
Visiting www.yourdomain.com when the certificate covers only yourdomain.com, or the reverse Visiting a subdomain not included in the certificate An alias domain with no certificate of its own Connecting to mail.yourdomain.com when AutoSSL has not covered the mail hostname The domain pointing at a server that hosts a different site
FIXING IT
- cPanel > SSL/TLS Status. Tick every domain, subdomain and alias.
- Run AutoSSL.
- Check each now shows a padlock.
If a subdomain will not issue, confirm it exists in DNS and resolves here.
FOR ALIASES
An alias redirecting to your main domain still needs its own certificate. A visitor typing the alias with https hits the certificate check before the redirect runs.
CHECKING WHAT IS COVERED
Click the padlock in the browser, view the certificate, and read the subject alternative names. That is the definitive list.