Safari "Cannot Establish a Secure Connection" on Mac? Fixes (2026)

You click a link, Safari thinks for a second, then throws up "Safari Can’t Establish a Secure Connection to the Server." The page never loads. It is one of the most common — and most misunderstood — Safari errors, and it almost never means your Mac has a virus.

What it actually means: Safari tried to set up an encrypted (HTTPS) connection to the site, and something in the handshake failed. That "something" is usually on your side and is quick to fix. Work through the list below in order — the first three fixes solve the large majority of cases.

First: is it one site or every site?

Try loading two or three unrelated HTTPS sites (your bank, apple.com, and a news site). This tells you where the problem lives:

  • Only one site fails → the problem is that site’s certificate, or a stale entry cached on your Mac. Jump to fixes 1, 4, and 5.
  • Every secure site fails → the problem is system-wide: your clock, DNS, a VPN/proxy, or a content blocker. Start at fix 2.

The fixes, fastest first

1. Reload in a Private window

Open a Private window (File → New Private Window, or Shift-Command-N) and try the site again. A private window ignores your cache, cookies, and most extensions. If it loads there, a cached entry or an extension is the culprit — go to fixes 5 and 6.

2. Check your date, time, and time zone — the #1 cause

This is the single most common reason for the error. Certificates are only valid within a date range, so if your Mac’s clock is wrong (even by a day), every certificate looks "expired" or "not yet valid" and the handshake fails.

Go to System Settings → General → Date & Time, turn on "Set time and date automatically," and set the time zone automatically too. If the clock jumps to the correct time after you enable it, reload the site — you are likely done. A dead logic-board battery on very old Macs can make the clock reset on every shutdown; if it keeps drifting back, that is worth a look.

3. Restart your Mac and your router

A full restart clears half-open network sockets and stale DNS state that a simple reload will not. Restart the Mac, and while it boots, power-cycle your router (unplug 30 seconds, plug back in). This alone fixes a surprising number of "every secure site fails" cases.

4. Flush the DNS cache

A poisoned or stale DNS entry can point Safari at the wrong server, whose certificate then fails to match. Flush it: open Terminal (Applications → Utilities) and run sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder, then enter your password. If the problem is DNS-related, switching to a reliable resolver like Cloudflare (1.1.1.1) or Google (8.8.8.8) often clears it for good — our guide to changing DNS on a Mac walks through it.

5. Clear this site’s data (not everything)

A corrupted cached certificate or cookie for one site triggers the error only on that site. In Safari, go to Settings → Privacy → Manage Website Data, search the site’s name, select it, and click Remove. Reload. Our clear-the-cache guide has the step-by-step if you want to be thorough.

6. Disable extensions and content blockers

Ad blockers, privacy extensions, and firewall tools like Little Snitch can silently block the certificate check or the connection itself. Turn them off in Safari → Settings → Extensions (uncheck each one) and try again. If a system-level content filter or antivirus is installed, temporarily disable it too. See managing Safari extensions for where everything lives.

7. Turn off any VPN or proxy

A VPN, corporate proxy, or a misconfigured proxy setting is a classic cause — the traffic gets re-routed through a server whose certificate Safari doesn’t trust. Disconnect any VPN app, then check System Settings → Network → (your connection) → Details → Proxies and make sure nothing is enabled that you didn’t set up yourself.

8. Check the site’s certificate trust in Keychain

If a single important site still fails, a certificate on your Mac may have been marked "Never Trust" by accident, or an old expired certificate is stuck. Open Keychain Access (Applications → Utilities), search for the site or its issuer, and confirm nothing is set to "Never Trust." Deleting a clearly expired duplicate certificate can also help. If certificate management feels murky, our Apple Passwords & Keychain explainer gives you the lay of the land first.

9. Update macOS

Apple ships the list of trusted root certificates with macOS. A Mac stuck on an old version can be missing newer roots, so freshly issued certificates fail. Go to System Settings → General → Software Update and install anything pending, then restart.

The honest part: when it is the hardware or the OS

Nine times out of ten this error is software. But if secure sites still fail after all of the above — especially if Wi-Fi also drops, the clock won’t hold, or the Mac is stuck on a macOS version too old to update — you may be looking at a failing Wi-Fi card, a dying board battery, or a Mac that has simply aged out of security updates. (If Wi-Fi is the real problem, our Wi-Fi keeps dropping guide is the better place to start.)

A Mac that can no longer run a supported, patched version of macOS is a genuine security risk for exactly this kind of encrypted-connection work — it is missing the newest root certificates and security fixes. If yours is at that point, upgrading to a certified refurbished Apple-silicon Mac is far cheaper than most people expect. Our Apple clearance section is where the best-value, fully-tested machines land, each backed by our own one-year warranty.

Frequently Asked Questions

Does "Cannot Establish a Secure Connection" mean my Mac has a virus?

Almost never. It is a failed HTTPS handshake, not malware. The usual causes are a wrong system clock, a DNS or VPN/proxy issue, a content blocker, or a bad cached certificate — all of which the fixes above address.

Why does it happen on only one website?

That points to a problem specific to that site: a corrupted cached certificate on your Mac (clear the site’s data, fix 5), a stale DNS entry (fix 4), or occasionally a genuinely expired certificate on the site’s own server — which only the site owner can fix.

The error is on every secure site. What now?

That is system-wide. Check your date and time first (fix 2), then disconnect any VPN (fix 7), disable content blockers (fix 6), and flush DNS (fix 4). One of those four resolves nearly every "all sites fail" case.

Chrome works but Safari shows the error — why?

Chrome and Safari can use different DNS settings and don’t share Safari’s cache or extensions, so a Safari-only cache/extension/certificate issue won’t affect Chrome. Start with fixes 1, 5, and 6.

Could an old MacBook be causing this?

Yes — if it can’t update to a macOS version that includes current root certificates, newer sites will keep failing and there’s no software fix. That is a sign the machine has aged out of security support; see our clearance MacBooks for an affordable, warrantied upgrade.

← All guides

Ready for a Mac that just works?

Every refurbished Mac from LuxuriousComputers comes with a 1-year warranty, 30-day returns, and saves you up to 55% vs retail.