Proving the Name
Lets encrypt vs paid SSL — A certificate is a statement about a name, and both kinds make the same one
You are wondering whether a paid certificate delivers anything the free one misses, and the useful way in is to ask what either is actually proving: control of a domain, demonstrated by an answer only its holder could have published.
The short answer
Take the free automated certificate unless something concrete overrides it — wildcard coverage across subdomains, verified company details, or a compliance document naming a paid product — because domain validation asks the same question of the same zone whoever charges for it.
The rest of this page is mechanism: how the proof is made, why a nameserver change can stop renewals silently, and which record decides who is allowed to issue for your name at all.
By the Hosting & Domains team · Reviewed 24 August 2026
99.9%
Uptime target, watched
24/7
Someone on the desk
Free
Certificate on every name
NVMe
Disks, all tiers
This page is for site owners wondering whether a paid certificate delivers anything the free one misses. It answers by looking at issuance rather than at price lists.
Browsers draw the same padlock whichever certificate you fitted, because the key exchange and cipher suites follow one code path. Price leaves no mark anywhere a visitor can see, which is why the free option wins on merit rather than on budget.
What domain validation actually asks
A DV certificate is issued after you demonstrate control of the name — either by publishing a token in the zone, or by serving one from the web root the name points at. That is the whole test, and it is identical whether the certificate cost nothing or cost a hundred pounds.
So the cryptography is the same, the padlock is the same, and the assurance is the same: this connection reaches whoever controls that domain. Nothing more was ever claimed by a DV product.
Paying an annual fee for a basic DV certificate technically indistinguishable from the automated free one is comfortably the commonest piece of dead weight on a small site's bill.
The renewal that stops without telling you
Automated certificates renew by repeating the proof, which means the proof has to keep working. Change the nameservers, move DNS to a new provider, or forget to recreate a validation record in the new zone, and renewal fails at a moment nobody is watching.
The symptom arrives weeks later as a browser warning on a site that had been fine for a year. It is a delegation problem wearing a certificate costume.
The habit that prevents it: after any nameserver or DNS provider change, check that the certificate still renews before the next expiry rather than after. One diary entry, one minute.
Who is allowed to issue for your name
A CAA record in your zone names the certificate authorities permitted to issue for the domain. Leave it absent and any authority may; publish it and only the ones you list may.
It is a small, cheap piece of control that also has a failure mode: add a CAA record naming one authority and then switch to a certificate from another, and issuance is refused with an error most people have never seen before.
So treat it as a deliberate decision rather than a default. If you publish CAA, write down which authority your automated renewals actually use.
Wildcards, and why they need the zone
A wildcard certificate covers every label at one level of a name, which is what makes it attractive when you have a dozen subdomains. It cannot be validated by serving a file, because there is no single web root for a name that does not exist yet.
Wildcards therefore require the DNS-based challenge: a token published in the zone. That is easy where you control the zone through the panel and awkward where DNS sits with somebody who charges for a support ticket.
Which is the real practical difference between free and paid in this market: not the encryption, but whether you can reach the records the automation needs.
What we would recommend, working shown. Taking the free automated certificate unless something concrete overrides it, whether wildcard coverage across subdomains, verified company details, or a compliance document naming a paid product.
In our range that means the DV SSL plan — SSL, the move and mail already inside, renewal charged at the order rate, and an upgrade path so this decision never has to be made twice.
A free SSL certificate comes with every plan and reissues itself before the old one lapses — the padlock is never yours to diarise.
Check first, trust after. Ask whether you can publish the records the automation needs, whether wildcards are supported, and what the renewal figure is in writing. That is the whole of the technical due diligence here.
Ours is Azaanex Inc., federally incorporated in Canada, on the public register.
The refund window covers the rest — bring a live site over, run it for two real weeks, and let ordinary use answer what no sales page can.

No paid placements, no referral fees
We sell paid certificates as well as including free ones, and this page still tells you the free one is usually correct. That is what an incentive looks like when it is disclosed rather than hidden.
Mailboxes at your own name are part of the plan — mail is included, not sold back to you at the checkout.
- Free certificates on every plan, reissued for you
- The zone reachable for DNS-based validation
- Wildcard and EV available where they are needed
- Renewal figures published, not footnoted
Why Hosting & Domains
Standard on every plan
Validation records you can publish
The zone is reachable from your own panel, which is what makes automated and wildcard issuance actually work.
An upgrade path that is real
Shared, VPS and dedicated on one platform — today's choice never boxes tomorrow in.
The verdict, turned into an order
The DV SSL plan is this page's conclusion in product form — one rate, essentials inside, upgradeable in place.
Reissue before expiry, unattended
The certificate renews itself ahead of the lapse date, so the padlock is never a diary entry you have to keep.
One rate, published in the open
What you order at is what you renew at — the only comparison that counts is one we win by default.
A refund without an argument
If we are not the fit, leaving is one request rather than a negotiation — which is why we invite the test.
Quick Start
Order placed to site online
- 1
Check renewal after every DNS change
A nameserver move is the commonest reason an automated certificate silently stops renewing. One diary entry after the change catches it months before a visitor does.
- 2
Decide about CAA deliberately
Publish it and only the authorities you list may issue for your name. Publish it carelessly and your own automated renewal is the thing it blocks.
- 3
Buy paid only against a written requirement
A wildcard you genuinely need, an organisation field a partner inspects, or a compliance document naming a product. Anything else is an annual fee for identical encryption.
Built In
Fitted to every plan
- Free SSL on every plan, reissued before the old one lapses
- A zone editor that can publish validation records
- Wildcard and EV certificates available where they are required
- WebP image optimisation built in, at no extra charge
- DDoS filtering absorbed at the network edge
- LiteSpeed caching in the server itself rather than bolted on by plugin
- The name's first year included when you order annually
- Money back within 30 days on hosting plans, 7 on reseller
- Upgrades applied in place, with no migration when you change plan
- 99.9% uptime as the target, watched around the clock
Frequently Asked
Questions we field again and again
How is a free certificate proved, exactly?
By demonstrating control of the name: publishing a token in the zone, or serving one from the web root the domain points at. A paid DV certificate is issued after the identical test, which is why the encryption and the assurance are the same.
Why did my certificate stop renewing after I changed nameservers?
Because the renewal repeats the proof, and the proof depends on the zone the name now delegates to. Move DNS without recreating what the automation needs and renewal fails quietly, surfacing weeks later as a browser warning.
What is a CAA record and do I need one?
It names the certificate authorities allowed to issue for your domain. It is useful control and a genuine trip hazard: list one authority, then switch to another, and issuance is refused. Publish it deliberately or not at all.
Why do wildcard certificates need DNS access?
Because there is no web root to serve a token from for a subdomain that does not exist yet, so the proof has to be published in the zone. If you cannot reach your own records, wildcards become a support ticket every time.
Keep reading
SSL Certificates
Free SSL on every plan, with wildcard and EV there when a written requirement calls for them.
CMS Hosting
Quick, hardened hosting for WordPress, Joomla, Drupal and every major CMS.
Changing provider? Work through this checklist beforehand.
A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.
One name, one padlock, no annual fee.
Free certificates that reissue themselves, a zone you can reach, and paid options only where they are genuinely required.
View SSL Certificates plans