Skip to content
UK web hosting, domain names, email, website security and online services.

Fix mixed-content warnings Print

  • troubleshooting, ssl
  • 0

Mixed content occurs when an HTTPS page loads scripts, images or other resources over HTTP.

Applies to: SSL certificates

An SSL certificate confirms control of a domain and encrypts traffic to the service named in the certificate. It does not make vulnerable application code safe, and it only covers the hostnames included in the certificate.

Before you start

  • Confirm the active product or addon and the domain or user it protects.
  • Record the current settings before changing them.

Work through these checks

  1. Use browser developer tools to identify insecure URLs.
  2. Update application and database URLs to HTTPS.
  3. Replace hard-coded external resources. Do not include the secret in a ticket, email or screenshot.
  4. Clear caches and retest.

Confirm the result

  • The service dashboard shows the intended setting or activation state after reload.
  • A live test from a separate session or device confirms that the customer-facing service works as expected.

Common problems

SymptomLikely causeWhat to do
The service does not show as active in its dashboard.Provisioning is pending, the wrong plan is selected or the service requires an additional activation step.Check the Customer Portal service status and order email, then open a ticket with the service ID instead of creating a duplicate order.
The dashboard setting is correct but the public result is not.DNS caching, an integration token, a device cache or a second service layer still uses the old value.Test from a separate session, check the integration and record exact timestamps before changing the setting again.

When to contact Tudor Internet

Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:

  • The addon service and protected domain or user
  • The plan or licence level
  • The time the issue started and exact message
  • Screenshots with credentials, tokens and personal data removed
Do not send passwords, private keys, full payment-card details, one-time authentication codes or unredacted identity documents in an ordinary support reply.

Related articles

Last reviewed: 2026-07-18.


Was this answer helpful?

« Back