Certificates · Beginner · 0–20 minutes
How to install an SSL certificate — A Certificate Is Issued to a Name, and Validated Through DNS
Certificates are not installed so much as earned: the authority checks that the name really points at this server, and everything that goes wrong goes wrong at that check.
The short answer
A certificate is issued against a hostname and validated by proving control of it, which on this platform means the name has to resolve here before anything can be issued. AutoSSL then does the work unprompted, usually finishing before you have got round to asking. Where issuance stalls, the fault is nearly always delegation rather than the certificate. Allow anything from 0 to 20 minutes, at beginner level.
The second half of the job is coverage. Every name in the account, plus www, plus each subdomain, needs to be listed — a certificate on one hostname while visitors arrive at another produces a warning that looks like catastrophe and is only a mismatch.
By the Hosting & Domains team · Reviewed 24 August 2026
Beginner
Assumed knowledge
5
Stages end to end
Free
Support cost
Proven
Verification
What you need: control of the name, access to whichever panel holds its zone, and 0–20 minutes. Every instruction is written against cPanel as we run it, and carries over to any standard cPanel account unchanged.
Read the part about what goes wrong before you open a zone editor. Nearly every ticket this topic produces arrives from somebody who reached that part second.
Issued to a name, proved through DNS
A certificate authority will not sign for a hostname without evidence that whoever asked controls it, and the evidence is either a DNS record or a file served at that hostname. Either way the check runs against the name as the world currently resolves it.
Which is why the whole subject belongs to whoever administers the domain rather than to whoever runs the server. Point the name here and the free certificate is issued and installed automatically; on a typical site the installation finished while you were still reading about it.
Coverage, name by name
SSL/TLS Status in the panel lists every domain and subdomain on the account with the state of its certificate against each. Green means done, and any warning names the exact hostname still waiting rather than leaving you to guess.
Both the www name and the bare domain want covering, and that happens automatically here — but check it, because traffic arriving at the uncovered one produces a browser warning far more alarming than the underlying problem deserves.
When issuance stalls, look at the delegation
AutoSSL cannot certify a hostname that does not resolve to this server. A name still delegated to a previous provider, an A record pointing at an old machine, a subdomain that was never created in DNS — all of them produce the same stalled state.
Correct the pointing, allow the old TTL to expire, and run the check again. Certificates follow DNS in the same way everything else does, and there is no way to hurry a validation that cannot yet see the name.
Free DV, wildcard, and what money buys
Buying a DV certificate because the site 'needs SSL' is money spent on nothing. The free automatic certificate encrypts identically; what the paid tiers add is organisational validation and wildcard scope, never a stronger padlock.
A wildcard is worth it when you genuinely run many subdomains, or create them faster than issuance can keep up. It covers one level — *.yourdomain — so a name two levels down still needs its own. For paid OV, EV or wildcard cover, create the CSR in the panel, send it to the authority and paste the signed result under Install SSL: five fields and five minutes.
Renewal is a DNS dependency too. Renewal only proceeds while the name still points at the issuing server. Once the delegation wanders off or the record breaks, renewal stalls and the certificate quietly lapses on its own schedule.
Restore the pointing and it picks up unaided, because the system keeps retrying in the background. The failure mode is worth understanding in advance, because it usually surfaces weeks after whatever DNS change actually caused it.

The account these records were published on
Every walkthrough here was carried out on the platform we operate — cPanel, LiteSpeed, NVMe, one-click installs — against a domain delegated to our own nameservers, so the screens described are the screens you get.
NVMe storage and LiteSpeed caching sit under every tier, the smallest plan included. That is the floor here rather than an upgrade.
- Registry, registrar, DNS host and mail host kept apart
- Every record shown at the name it belongs on
- The clock on each change stated as a number
- A desk that answers at any hour you stall
Why Hosting & Domains
Standard on every plan
Written out of the ticket queue
These pages exist because the same questions kept arriving. Every warning on them is one somebody has genuinely needed.
Honest about the size of it
Getting a certificate onto every name is beginner-level work — allow 0–20 minutes, with the stages the account already handles marked as such.
Registry, registrar, host — kept apart
Each term is defined where it first appears, or linked to the jargon buster. Nothing here uses the four words as though they meant one thing.
The way back, printed beside the way in
Anything carrying a clock or a lock is marked, together with exactly how to reverse it.
Help on your clock, not ours
Stuck at the zone editor at midnight? The desk answers at any hour, mid-walkthrough included.
Stages, not padding
Each stage is a few minutes of careful clicking, and the parts that genuinely need care are marked as such.
Quick Start
Order placed to site online
- 1
Point the name here and let AutoSSL do the work
Issuance begins as soon as the hostname resolves to this server. On a typical site the certificate is installed before anybody thinks to check, which is the intended experience.
- 2
Read SSL/TLS Status name by name
The panel lists every domain and subdomain with the state of its certificate. Green is done; a warning names the exact hostname still waiting, which saves you guessing at which one is uncovered.
- 3
Fix the delegation for anything still waiting
A stalled name is nearly always a DNS problem: still delegated elsewhere, an A record aimed at an old machine, or a subdomain that was never created. Correct it, let the old TTL run out, then re-run the check.
- 4
Buy a certificate only where you need OV, EV or wildcard cover
Create the CSR in the panel, send it to the certificate authority, paste the signed result under Install SSL. Five fields and five minutes — and unnecessary for ordinary encryption, which the free certificate already provides.
- 5
Confirm the redirect sends people to the covered hostname
Issuing the certificate is half the job. The https redirect, on by default here, is what makes sure visitors arrive at the name the certificate actually covers rather than at the one it does not.
Built In
Fitted to every plan
- cPanel, the panel most of the industry already standardised on
- Webmail in the browser, plus IMAP, POP and SMTP for any client
- 30 days back on hosting plans, 7 on reseller
- The first year of the name included when you order annually
- Your existing site brought across by our engineers at no charge
- LiteSpeed caching built into the server rather than bolted on by plugin
- No set-up charge at any point, and no joining fee
- A desk staffed every hour of every day
- WordPress and 400+ other applications in one click
- Softaculous bundled, for one-click application installs
Frequently Asked
Questions we field again and again
My certificate lapsed instead of renewing. What broke?
Almost certainly the pointing. Renewal only proceeds while the name still resolves to the issuing server, so a delegation change, a replaced A record or a nameserver move stalls it silently. Restore the pointing and it resumes on its own, because the system keeps retrying in the background — the lapse is a symptom of a DNS change, not of the certificate.
Do I need a wildcard for my subdomains?
Usually not. AutoSSL covers each subdomain individually as it is created, which is fine for a handful. A wildcard earns its cost when you run many subdomains or create them faster than issuance keeps up — and note it covers exactly one level, so a hostname two levels down still needs cover of its own.
Is the free certificate genuinely free, on every plan?
Entirely, on every plan, issued as soon as the name points here and reissued well before it lapses. On encryption it is identical to any paid DV certificate; the paid options exist for wildcard coverage or organisation validation, neither of which most sites ever need.
Will you move my existing site across at no charge?
Yes. Open a ticket with the login for your current host and we bring the lot — files, databases, mailboxes, configuration. You check the copy before any DNS moves, and the old site keeps taking traffic right up to the moment the new one serves it.
Keep reading
AI Website Builder
Describe what you need and the AI drafts the site on real hosting.
WordPress Hosting
WordPress looked after for you: LiteSpeed caching, staging copies and a daily backup.
Changing provider? Work through this checklist beforehand.
A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.
One rate, this year and next.
Free SSL, a free migration, renewals billed at the original rate, and a desk staffed around the clock. That is the whole of the offer.
View AI Website Builder plans