ERR_SSL_BAD_RECORD_MAC_ALERT means the client or server received a TLS record with an invalid MAC (Message Authentication Code). The data was corrupted in transit: network glitch, proxy, antivirus doing TLS inspection, or bad RAM. Fix: disable AV TLS inspection, check MTU, update network drivers.
This error blocks HTTPS access. Below: causes, fixes, working config, FAQ.
ping -M do -s 1472 8.8.8.8; if fragments — lower to 1400ethtool -K eth0 tso off gso off gro off (disable offload)server {
listen 443 ssl http2;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256;
ssl_prefer_server_ciphers off;
ssl_stapling on;
ssl_stapling_verify on;
}SSL/TLS is the encryption protocol that protects data between the browser and server. Our tool analyzes the certificate, chain of trust, TLS version, and knownvulnerabilities.
Issuer, validity period, signature algorithm, covered domains (SAN), and validation type (DV/OV/EV).
Full chain verification: from leaf certificate through intermediates to root CA.
Protocol version (TLS 1.2/1.3), cipher suites, Perfect Forward Secrecy (PFS) support.
Set up a monitor — get Telegram and email alerts 30/14/7 days before expiration.
SSL certificate monitoring
TLS config audit
HTTPS as ranking factor
customer trust
www and subdomains.Strict-Transport-Security header forces browsers to always use HTTPS.SSL certificate monitoring, check history and alerts 30 days before expiry.
Sign up freeMessage Authentication Code — a cryptographic hash embedded in every TLS record. It verifies data integrity in transit. Bad MAC = data was corrupted.
Usually not. Mostly hardware/software bugs. But constant bad MACs can hint at a MITM attack (very rare).
TLS inspection decrypts traffic, injects its own cert, re-encrypts. Bugs → MAC does not match.
Mobile networks often have lower MTU (1400–1460). Desktop over WiFi — 1500. The delta → fragmentation at the TLS layer.