Somebody points a new domain at their website, checks it in the browser, and there it is: "Not secure," sometimes with a red warning triangle right in front of the address. For a business owner, that's a small moment of dread. Did something break? Is a customer about to see this and bounce?
Usually, no. But the warning is real, so here's what it actually means and what fixes it.
That padlock, or the lack of one, is about the connection between a visitor's browser and your server, not your website's content. An SSL certificate encrypts that connection so nobody on the same coffee shop wifi can read what a customer types into your contact form. Browsers have gotten aggressive about flagging sites without one, which is fair. It's also why a brand-new domain, even a perfectly fine one, can show that warning for a bit before it clears up.
On Cantrip, you don't buy a certificate or install anything. Every site gets HTTPS automatically, whether it's living on your free cantrip.io subdomain or a domain you bought yourself. Point a custom domain at Cantrip on a paid plan, and SSL turns on for it the same way, at no extra charge. There's no toggle to flip because there's nothing to configure. It just follows your DNS.
Which is exactly why the warning shows up right after connecting a new domain. Your domain provider has to update its records, those records have to propagate across the internet, and only then can a certificate get issued for that exact address. In your Cantrip domain settings you'll see it labeled "Pending SSL" during that window and "Valid SSL" once it clears. That's normal, and it usually resolves within a few hours of the DNS being correct, not from the moment you type in an IP address.
The part worth checking yourself: the A record has to point at exactly the right IP address, for both the bare domain and the www version if you're using one. Get that wrong (a typo, an old record from a previous host still hanging around) and "Pending SSL" just sits there, because the connection genuinely can't be verified. A support ticket won't fix a DNS record. Re-checking the record will.
I used to sell SSL certificates as a $70-a-year add-on back when that was just how the industry worked: buy the cert, install it, remember to renew it before it expired and your whole site went red for a week. That business model shouldn't exist for a basic small business website anymore. It's baked in now, on every plan, one less bill and one less thing to remember.