Every domain on your account is entitled to a free AutoSSL certificate, issued and renewed automatically at no cost.
ISSUING ONE
- Point the domain at the nameservers shown in your Client Area. AutoSSL cannot validate a domain that does not resolve here.
- cPanel > SSL/TLS Status.
- Tick the domains and subdomains.
- Click Run AutoSSL.
- Wait a few minutes and refresh. A green padlock means it is active.
Renewal happens automatically about a month before expiry, with nothing required from you.
AFTER ISSUING
Set your application's site address to the https:// version, then switch on Force HTTPS Redirect under cPanel > Domains.
IF IT FAILS
Click the domain name on the SSL/TLS Status page to see the exact reason. The usual causes are: the domain is not yet resolving to us, it is proxied through Cloudflare in a mode that blocks validation, a redirect is intercepting the /.well-known/ path, or the subdomain does not exist in DNS.
WHEN YOU MIGHT PAY FOR A CERTIFICATE
Organisation-validated or extended-validation certificates, or a certificate carrying a warranty, for compliance reasons. For the vast majority of sites, the free certificate is technically identical in the browser.