How a certificate works
A certificate is a small file installed on your server that does two jobs. It contains the public half of a cryptographic key pair, which lets a browser establish an encrypted connection, and it carries a statement from a certificate authority confirming that the key belongs to your domain. Without the second part, the encryption would be private but anonymous.
SSL and TLS are the protocols themselves. SSL is the older family and has been retired; TLS replaced it and is what every current browser uses. The industry kept saying SSL certificate out of habit, so today the two names describe the same purchase.
When a visitor arrives, the browser checks that the certificate matches the domain, has not expired, and traces back to an authority it trusts. If all three hold, the connection is encrypted and the page loads over HTTPS. If any one fails, the browser shows a full-page warning instead of the site.
Why certificates matter
Encryption protects anything a visitor types — an enquiry form, a login, card details — from being read or altered in transit. On public wifi that is not theoretical; unencrypted pages can be modified before they ever reach the browser.
The visible consequence is trust. Browsers mark pages without a valid certificate as not secure, and an expired one produces an interstitial warning that most people will not click past. An expired certificate does not reduce traffic gradually. It stops it.
Where certificates go wrong
Expiry is the most common failure, and it usually happens because a certificate was issued manually and then forgotten. Free automated certificates renew themselves; paid ones often do not, and the reminder goes to an email address nobody monitors any more.
Coverage is next. A certificate issued for one hostname does not cover others, so a shop that also runs a subdomain for a blog or a booking system can secure one and warn on the other. Wildcard certificates exist for exactly that situation.
Then there is a certificate that is valid while the pages are not. Images, scripts or fonts still requested over plain HTTP produce mixed content, and browsers block or downgrade the page even though the certificate is fine.
What to do about it
Use an automatically renewing certificate wherever your host supports one, and check that the renewal actually runs rather than assuming it does. Put an expiry reminder in a shared calendar rather than one person’s inbox.
After any installation, load the site and confirm three things: every hostname you use is covered, every internal link and asset points at the secure address, and old insecure URLs redirect once to their secure equivalent rather than through a chain of hops. Paid certificates earn their cost only when you need wider coverage, validated organisation details or a warranty; for the encryption itself, a free automated certificate does the same work.