NET::ERR_CERT_COMMON_NAME_INVALID: certificate doesn't match the domain

The certificate is for a different name. www vs bare domain, wildcard limits, default certificates and DNS pointing elsewhere.

· 3 min read · By the Spot Downtime team

NET::ERR_CERT_COMMON_NAME_INVALID means the certificate is real and unexpired, but it's for a different name than the one in the address bar. You asked for www.example.com and the server presented a certificate for example.com, or for a different site entirely. Firefox calls it SSL_ERROR_BAD_CERT_DOMAIN.

Check which names the certificate covers

A certificate lists every hostname it's valid for in its Subject Alternative Names. Browsers only accept exact matches, plus wildcards one level deep:

SSL certificate checkerSee every name a site's certificate covers, and whether the one you're visiting is among them.
bash
openssl s_client -connect example.com:443 -servername www.example.com </dev/null 2>/dev/null \
  | openssl x509 -noout -ext subjectAltName

Common causes

www vs the bare domain

The certificate covers example.com but not www.example.com, or the reverse. Include both names when you request it:

bash
sudo certbot --nginx -d example.com -d www.example.com

Wildcards only go one level

*.example.com covers app.example.com but not example.com itself, and not api.eu.example.com. Add the bare domain and any deeper names explicitly.

The server serves its default certificate

A server hosting several sites picks a certificate by the hostname the browser sends (SNI). If there's no HTTPS site configured for this name, it falls back to the default, which belongs to another site. Add a server block for the hostname with its own certificate.

DNS points to someone else's server

A domain pointing at a hosting provider, CDN or old server that doesn't know about it gets that server's certificate. Common after a migration or a half-finished CDN setup.

DNS lookupCheck where the hostname points, and whether it matches the server you configured.

For visitors

This one is worth taking seriously: the site you reached can't prove it's the site you asked for. Don't enter passwords or payment details. Try the address with or without www, or let the site owner know.

Catch it automatically: Spot Downtime's HTTPS checks fail when a certificate is mismatched, untrusted or expired, so you hear about it on the first check rather than from a customer screenshot. See SSL monitoring.

Keep reading