“Your Connection Is Not Private” on iPhone

What an HTTPS certificate warning actually means on iPhone, which kinds are dangerous, and why the safe answer is almost never to tap through.

Updated August 2026

Quick answer

It means your browser could not verify that the site is who it claims to be — so anything you type could be read or altered in transit. The three common causes are an expired certificate, a self-signed one, and a name mismatch (the certificate belongs to a different domain). On a public network, or on any site where you would enter a password or card number, treat it as a stop sign rather than a warning: leave and reach the site another way.

What the warning actually means

HTTPS does two separate jobs. It encrypts the connection, and it proves the server on the other end really controls the domain in the address bar. A certificate warning means the second job failed. Encryption may still be happening — but encrypting a conversation with a stranger who is impersonating your bank is not much comfort.

This is why “it's just a warning, the padlock is only for shopping sites” is bad advice. The padlock is about identity, and identity is exactly what is in question.

The four causes, and how worried to be

What went wrongTypical innocent causeReal risk
ExpiredSomeone forgot to renew — extremely common on small or internal sitesLow on its own, but you cannot tell an expired certificate from a stolen one by looking
Self-signedA router login page, a home NAS, a dev serverFine on hardware you own; on a public website it is a strong warning sign
Name mismatchSite served from the wrong hostname, or a stale redirectHigh — this is what an interception attack looks like
Untrusted issuerA corporate or school network inspecting trafficHigh outside that context — it means something is sitting between you and the site

Bear in mind the innocent explanation and the attack look identical from the outside. That is the whole problem: the warning exists precisely because your device cannot tell them apart.

What to do when you see one

  1. 1

    Do not enter anything

    No passwords, card numbers, or personal details — not even on the page after the warning.

  2. 2

    Check the address bar carefully

    A certificate error alongside a slightly-off domain name is a much worse sign than either alone.

  3. 3

    Leave the network out of the equation

    If you are on café or hotel Wi-Fi, switch to cellular and try again. If the warning disappears, the network was the problem — which is itself worth knowing.

  4. 4

    Reach the site another way

    Type the address yourself, or use the company's app. Do not follow the link that produced the warning.

  5. 5

    Only proceed on hardware you own

    Your own router's admin page will legitimately be self-signed. A bank never will be.

How Avodek handles it

Avodek checks each page you open and warns before loading a site whose certificate is expired, self-signed, or otherwise invalid. It names which of those went wrong, rather than showing one generic message.

The deliberate difference: certificate problems cannot be bypassed. There is no “proceed anyway” link — the only option takes you back. That is a stricter stance than most browsers take, and it is a considered trade-off: the times a person taps through a certificate warning correctly are vastly outnumbered by the times they should not have.

Avodek also upgrades over 1,000 major sites to HTTPS automatically, so a downgrade to plain HTTP is caught rather than quietly accepted.

Common questions

Is it safe to continue if I trust the site?

Trusting the site is not the question — the warning means your device cannot confirm you are talking to that site at all. Someone intercepting the connection would produce exactly this warning on a domain you trust.

Why does it only happen on some networks?

Because some networks inspect or redirect traffic. Captive portals on hotel and airport Wi-Fi commonly trigger it before you sign in; corporate and school networks may install their own inspecting certificate. If switching to cellular clears it, the network was intercepting.

Can an expired certificate really be dangerous?

The expiry itself is usually just neglect. The danger is that expiry disables the check that would otherwise catch a stolen or forged certificate, so you lose the guarantee at the exact moment you would want it.

Why won't Avodek let me continue anyway?

By design. Phishing and interception attacks rely on people tapping through, so Avodek removes the option for certificate failures rather than making it slightly inconvenient.

Related guides

Get Avodek

Private Browser + AI · Free on the App Store.

Learn more about Avodek