Skip to main content

Certificates & Trust

SSL certificates: the name is what gets vouched for

The padlock works on one version of your address and warns on the other, and nothing about the server has changed.

The short answer

An SSL certificate is the credential that switches on encrypted HTTPS and attests that whoever holds it genuinely controls the names listed on it.

Read that twice, because the second half is the useful part. A certificate is issued to hostnames, not to a server, and the evidence behind it is control of the name, demonstrated either through a file in your web root or a record in your DNS zone.

Which is why certificates are a domains subject. Every certificate question is ultimately a question about which names you hold, which of them resolve here, and who is allowed to ask for a credential in their name.

By the Hosting & Domains team · Reviewed 18 August 2026

100+

Entries in the domain dictionary

2 min

To read one entry

Plain

English, all the way through

24/7

Someone on the desk, always

The correct term is a TLS certificate, though the older name never went away. Each one ties a public key to one or more hostnames and carries the signature of a certificate authority browsers already trust. The padlock is the visible end of that chain.

Automation rewrote the economics of all this. Issuing and renewal are now machine work costing nothing, and every plan we run works that way. Paid tiers survive for wildcard convenience and organisation-level validation, where somebody's paperwork insists on it.

The certificate names hostnames, not machines

Open any certificate and you will find a list of names it covers. A browser compares the hostname you typed against that list, and if it is absent you get a warning however healthy the server is and however valid the certificate.

Move a site to a new server and the certificate follows the names, not the hardware. Add a new hostname and the existing certificate does not know about it. Practically every mystery padlock warning is a name that was never on the list.

How control of a name is actually proved

Two routes. The HTTP route asks you to serve a specific file from the web root of the name, which requires the name to be resolving here already. The DNS route asks you to publish a specific TXT record in the zone, which requires nothing to be resolving anywhere and needs you, or your provider, to be able to edit records.

The practical consequence catches people mid-migration. Before delegation moves, only the DNS route can prove control at the new host, because the HTTP route would still be answered by the old one.

CAA: the record that says who may issue for your name

A CAA record in your zone lists the certificate authorities permitted to issue for that name, and conforming authorities check it before they issue anything. Publish one naming a single authority and every other one is instructed to refuse.

It is a genuine control worth having, and a genuine trap worth knowing about. A CAA record left behind from a previous arrangement will block a new host's automation with an error nobody thinks to look for, because the failure is in your zone rather than in the request.

www, non-www, and the name you forgot

A certificate for example.com does not cover www.example.com. They are two names and both need to be on the credential, which the automation here handles as a matter of course, and which manual issuance regularly gets half right.

Then there are the names nobody thinks about: the defensive registration you bought to stop somebody else having it, the misspelling that redirects, the ccTLD you kept for a market you never entered. Each is a hostname a visitor can type, and each will produce a warning if it answers without cover.

Expiry, automation and the tiers that survive. An expired certificate stops visitors with a full-page warning: instant, total, embarrassing. Automatic renewal, the default here, exists so expiry never becomes an event at all. Install one by hand and somebody has to own a date in a calendar.

Read on into Let's Encrypt, HTTPS, Wildcard Certificate and DV, OV and EV Validation. A copy is taken daily on every plan, and putting a file or a database back is one click in the panel.

A key resting on a keyboard, for the certificate every domain here is issued

A dictionary written from the registry outwards

A term nobody explained is, to us, a service defect. This is the desk's own collected vocabulary, published where a search engine can hand it over on our behalf.

NVMe storage and LiteSpeed caching sit under every tier, the smallest plan included — that is the floor here, not an upgrade.

  • 100+ entries, written in plain English
  • Registry, registrar, reseller and host kept apart
  • The record, the clock and the failure mode named
  • Written by the people who run the transfers

Why Hosting & Domains

Standard on every plan

Written from the registry outwards

Every entry says where the record actually lives, and which of registry, registrar or host owns it.

The failure mode, not just the definition

Each term arrives with the thing that breaks when it is wrong — usually email, and usually quietly.

Examples from real zones

Record names, selectors and hostnames as you would actually type them, rather than an abstract diagram.

SSL/TLS Certificate, located

SSL/TLS Certificate defined, tied back to the names it covers, and pointed at where issuance really happens.

Cross-referenced on purpose

Neighbouring records and protocols point at each other, so one lookup turns into working knowledge.

Says how deep to go

Most of these you only ever need to recognise. Where a term genuinely has to be operated, the entry says so.

Quick Start

Order placed to site online

  1. 1

    Find the record, not the setting

    Open the DNS zone for the name and read what is actually published there. A term stops being abstract the moment you see it in your own zone.

  2. 2

    Work out who owns the setting

    Registry, registrar, DNS host, mail host: only one of the four can change the thing in front of you. Establish which before you change anything.

  3. 3

    Read the neighbouring entries

    Names travel in groups — Let's Encrypt, HTTPS and Wildcard Certificate complete this one's picture, each a two-minute read away.

Built In

Fitted to every plan

  • LiteSpeed caching inside the server, not bolted on by plugin
  • WordPress and 400+ further applications in a single click
  • Money back inside 30 days on hosting, 7 on reseller
  • DDoS filtering taken at the network edge
  • NVMe SSD storage under every tier, not only the dear ones
  • cPanel — the panel most of the industry already runs
  • 99.9% uptime as the target, watched every hour of the day
  • A copy taken daily, and restores you run yourself
  • WebP image optimisation included, nothing added to the invoice
  • Mailboxes that answer at the name you own

Frequently Asked

Questions we field again and again

Is a certificate tied to the server or to the name?

To the names listed on it. That is why a certificate survives a move to different hardware and why adding a new hostname invalidates nothing but covers nothing either. When a padlock warning appears, the first question is which name the visitor actually typed.

Why did issuance fail with a CAA error?

Because your zone contains a CAA record naming certificate authorities, and the one being asked is not among them. Conforming authorities check that record and refuse politely. It is a common leftover from a previous host or a previous certificate vendor, and the fix is an edit in the zone rather than anything at the host.

How do I get a certificate before the name points here?

Through the DNS route. Publishing the required TXT record proves control without any traffic having to arrive, so the credential can exist before delegation moves. Doing it in that order is what lets you check a migrated site over HTTPS before anybody else can reach it.

Who stands behind Hosting & Domains?

Hosting & Domains is a trading name of Azaanex Inc., federally incorporated in Canada, with a public filing and terms governed by Ontario law. Before you hand any company control of a name, that is a check worth five minutes.

Keep reading

  • Agency Hosting

    Client accounts, staging and care-plan infrastructure arranged for agencies.

  • Web Hosting

    cPanel hosting on NVMe drives, with SSL, the migration and year one of the name included.

Changing provider? Work through this checklist beforehand.

A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.

You get the checklist, followed now and then by a note on keeping a site responsive. Unsubscribe whenever you want; the privacy policy covers the rest.

Every name you hold, covered.

Free SSL, a free migration, renewals at the rate you registered at, and a person on support at any hour.

View Agency Hosting plans