The SSL_ERROR_BAD_CERT_DOMAIN error for email click tracking domains stems from various causes related to SSL certificate configuration and domain setup. Common issues include a mismatch between the domain name on the certificate and the actual domain, often due to missing subdomains in the Subject Alternative Name (SAN) list, expired certificates, or the absence of SSL altogether on the click tracking domain. Problems with the certificate chain, CDN configurations, shared hosting limitations, DNS propagation delays, mixed content (HTTP resources on an HTTPS site), and incorrect entries in the hosts file can also trigger the error. Cloudflare's Flexible SSL setting may contribute, as it only encrypts traffic between the visitor and Cloudflare. Additionally, incorrect redirect configurations, and Server Name Indication (SNI) issues can be the cause. While the error doesn't directly impact email deliverability, it lowers click-through rates (CTR). To resolve the issue, it is best to ensure SSL is properly implemented, checking certificate details, verifying the CDN and server configuration, and that all resources are loaded over HTTPS. Contacting the ESP or hosting provider, or switching to a different hosting provider may be necessary.
11 marketer opinions
The SSL_ERROR_BAD_CERT_DOMAIN error for email click tracking domains arises from various SSL certificate and domain configuration issues. Common causes include expired certificates, domain name mismatches in the certificate, missing subdomains in the Subject Alternative Name (SAN) list, and incorrect certificate chains. Problems with Content Delivery Networks (CDNs), shared hosting SSL limitations, DNS propagation delays after certificate installation, mixed content (HTTP resources on an HTTPS site), and incorrect entries in the hosts file can also trigger this error. Additionally, misconfigured redirects, and Server Name Indication (SNI) issues can contribute to the problem. Troubleshooting involves checking certificate details, ensuring proper CDN and server configuration, verifying DNS settings, and confirming that all resources are loaded over HTTPS. Consulting the ESP's support resources or getting a dedicated SSL certificate might also be required.
Marketer view
Email marketer from Namecheap Forum explains that on shared hosting, the SSL certificate may not cover the specific subdomain. This can lead to a mismatch error. He recommends contacting the hosting provider to get a dedicated SSL certificate for the subdomain or using a wildcard certificate.
26 Jun 2023 - Namecheap Forum
Marketer view
Email marketer from Email Geeks suggests checking the ESP's support articles to determine if they support SSL on tracking domains. If not, a reroute through a domain host that supports SSL may be necessary.
30 Sep 2023 - Email Geeks
3 expert opinions
The SSL_ERROR_BAD_CERT_DOMAIN error for email click tracking domains often stems from the domain lacking SSL setup, leading browsers to attempt secure connections with mismatched default certificates. SSL configuration problems linked to hosting services that don't fully support SSL certificates for click-tracking domains are also a factor. While this error typically won't cause emails to be blocked by ISPs, it can significantly reduce click-through rates due to users encountering the security warning.
Expert view
Expert from Email Geeks explains that the SSL error won't cause ISPs to block emails, but it will lower the successful click-through rate (CTR) because some users will encounter the error.
16 Jan 2025 - Email Geeks
Expert view
Expert from Email Geeks explains that the SSL error is likely caused by the click tracking domain not having SSL set up, which leads to the browser trying to force a secure connection (HTTPS) and getting a default SSL certificate that doesn't match the domain name, the fix is to implement SSL for the domain and fully implement SSL.
20 Jul 2024 - Email Geeks
5 technical articles
The SSL_ERROR_BAD_CERT_DOMAIN error arises from several SSL configuration issues. Key causes include a mismatch between the domain name on the certificate and the website's domain, often due to the certificate being for a different domain or lacking the specific subdomain in its Subject Alternative Name (SAN) list. Incomplete or incorrectly configured certificate chains, where intermediate certificates are missing, can also cause this error. Browser-specific caching can sometimes contribute. If using Cloudflare, Flexible SSL settings may be problematic, as encryption only occurs between the visitor and Cloudflare, not between Cloudflare and the origin server; Full or Strict SSL settings are recommended for end-to-end encryption.
Technical article
Documentation from Mozilla Support explains the error is browser specific and clears out any caching.
26 Apr 2022 - Mozilla Support
Technical article
Documentation from Cloudflare explains when using Cloudflare's flexible SSL setting, it can cause issues. Cloudflare only encrypts the connection between the visitor and Cloudflare, not between Cloudflare and the origin server. This can lead to SSL errors if the origin server doesn't have a valid certificate. They recommend using Full or Strict SSL settings for end-to-end encryption.
23 Mar 2022 - Cloudflare Support
Are HTTP links penalized by spam filters in email marketing?
Besides Spamhaus, what blocklists are important for email marketers to monitor?
Do secure HTTPS links improve email deliverability?
Does SSL certificate type affect email deliverability?
Does using HTTP links instead of HTTPS links affect email deliverability?
Does website SSL/TLS affect email deliverability?
How can I determine if third-party links in email affect deliverability?
How does sending domain differing from click tracking domain affect email deliverability?
What are best practices for warming up a new subdomain for email sending, and how does it impact DKIM alignment?
What are the best practices for using domains and subdomains for email click tracking to avoid spam filters?