What an SSL certificate does and where to get one
An SSL certificate is a file that encrypts the connection between a visitor's browser and your website. When someone visits a site with SSL, their browser shows a padlock icon and the address bar displays "https://" instead of "http://". Without SSL, any data they enter — passwords, credit card numbers, personal information — travels unencrypted across the internet.
You obtain an SSL certificate from a certificate authority (CA), which is an organization that verifies you own the domain and issues the certificate. Common certificate authorities include Let's Encrypt (free), Sectigo, DigiCert, and GoDaddy. Your web hosting provider may also sell certificates directly or offer them included with your hosting plan.
The process takes anywhere from a few minutes to a few days depending on the certificate type and how quickly you respond to verification requests. Most small business websites and personal sites use a basic certificate that costs nothing to $100 per year.
Key Takeaways
- Let's Encrypt offers free SSL certificates and works with most hosting providers, making it the lowest-cost option for most websites.
- You need to prove you own the domain before any certificate authority will issue a certificate, usually by adding a DNS record or uploading a file to your website.
- Your web hosting provider may include SSL for free or sell it as an add-on; check your hosting account before buying elsewhere.
- Once installed, the certificate renews automatically with most providers, but you should confirm this is set up so your site does not lose encryption.
Check what your hosting provider includes
Before you buy an SSL certificate, log into your web hosting account and look for a section called "SSL", "Security", "Certificates", or "HTTPS". Many hosting providers now include a free basic SSL certificate with every plan, especially if you are using WordPress hosting, Shopify, Wix, or similar platforms.
If your provider includes SSL, they usually install it automatically or provide a one-click button to activate it. You do not need to do anything else — the certificate renews on its own. If your provider does not mention SSL in the account dashboard, contact their support team and ask whether SSL is included or what the cost is.
This step saves you money and time because you avoid buying a certificate you already own. It also means your hosting provider handles renewal automatically, which prevents your site from losing encryption if you forget to renew manually.
Use Let's Encrypt if your provider does not include SSL
Let's Encrypt is a free certificate authority run by a nonprofit organization. It issues standard SSL certificates at no cost, and the certificates work exactly like paid ones — browsers trust them equally. The only limitation is that Let's Encrypt certificates expire every 90 days, but renewal happens automatically if your hosting provider supports it (most do).
To use Let's Encrypt, you need access to your hosting account's control panel or the ability to install software on your server. If you use a hosting provider with a control panel like cPanel or Plesk, there is usually a one-click button to install a Let's Encrypt certificate. Search your hosting provider's help documentation for "Let's Encrypt" or "free SSL" to find the exact steps.
If you manage your own server or use a provider without a control panel, you can use a tool called Certbot to install and renew Let's Encrypt certificates automatically. Certbot is free software that runs on your server and handles the entire process without your involvement after setup.
Prove you own the domain
Every certificate authority requires proof that you own or control the domain before they issue a certificate. This prevents someone else from getting a certificate for your domain and impersonating your site. The verification process takes a few minutes to a few hours and uses one of three methods.
DNS verification is the most common method. The certificate authority gives you a DNS record to add to your domain's settings. You log into your domain registrar (GoDaddy, Namecheap, Google Domains, etc.), find the DNS settings, and add the record exactly as instructed. Once the record is live, the certificate authority checks for it and issues your certificate. This method works even if your domain and hosting are with different companies.
File verification requires you to upload a small text file to your website's root directory. The certificate authority then visits your website, looks for that file, and issues the certificate if it finds it. This method is faster than DNS verification but only works if your website is already online.
Email verification is the oldest method. The certificate authority sends an email to an address associated with your domain (like admin@yourdomain.com or the email listed in your domain registration). You click a link in the email to confirm you own the domain. This method is less common now because it is slower and less reliable.
Buy a paid certificate if you need advanced features
A free Let's Encrypt certificate works for most websites, but some situations call for a paid certificate. If you run an e-commerce site, handle sensitive customer data, or want extra trust signals, a paid certificate from Sectigo, DigiCert, or your hosting provider may be worth the cost.
Paid certificates come in three types. A Domain Validated (DV) certificate is the basic option — it proves you own the domain but does nothing else. It costs $10 to $50 per year and is identical to a Let's Encrypt certificate in how browsers treat it. A Organization Validated (OV) certificate proves you own the domain and that your organization is real and registered. Browsers display your organization name in the certificate details, which some customers find reassuring. OV certificates cost $100 to $300 per year. An Extended Validation (EV) certificate is the most expensive and most thorough — the certificate authority investigates your business, verifies your legal documents, and confirms you are who you claim to be. Browsers may display your company name in the address bar itself. EV certificates cost $200 to $500 per year.
For a personal blog, small business website, or nonprofit site, a free Let's Encrypt certificate is sufficient. For a bank, insurance company, or large e-commerce site, an EV certificate may justify the cost because it signals to visitors that you have passed rigorous verification.
Install the certificate on your website
Once you have obtained a certificate, you need to install it on your web server so it actually encrypts connections. If your hosting provider installed the certificate for you (either included or through a one-click button), this step is already done — you do not need to do anything.
If you obtained the certificate yourself, your hosting provider's control panel usually has a section to upload and install it. Look for "SSL", "Certificates", "HTTPS", or "Security" in your control panel. You will paste the certificate file and the private key file into the designated fields. The exact steps vary by hosting provider, so search their help documentation for "install SSL certificate" or contact their support team.
After installation, visit your website in a browser and look for the padlock icon next to the address bar. Click the padlock to verify the certificate is installed correctly and shows your domain name. If you see a warning or error, the certificate is not installed properly — contact your hosting provider's support team with a screenshot of the error.
Set up automatic renewal
SSL certificates expire after a set period — Let's Encrypt certificates expire every 90 days, while paid certificates usually expire after one or three years. If your certificate expires and you do not renew it, your site will show a security warning in browsers and visitors may leave.
Most hosting providers set up automatic renewal by default, especially for Let's Encrypt certificates. Log into your hosting account and look for a section about SSL or certificates to confirm renewal is enabled. If you see a renewal date listed, automatic renewal is active. If you do not see renewal information, contact your hosting provider and ask them to enable it.
If you manage your own server, Certbot (the Let's Encrypt tool) includes automatic renewal as part of its setup. After you install Certbot, renewal happens in the background without your involvement. For paid certificates, you usually need to renew manually through your certificate authority's website, though some hosting providers offer automatic renewal for paid certificates too.
Frequently Asked Questions
Can I move an SSL certificate to a different hosting provider?
It depends on the certificate type. Let's Encrypt certificates are tied to your domain, not your hosting provider, so you can reinstall them on a new host. Paid certificates are usually tied to a specific domain but not a specific host, so you can move them — contact your certificate authority to transfer it. Some hosting providers charge a transfer fee or require you to buy a new certificate instead.
What happens if my SSL certificate expires?
Browsers will display a security warning when visitors try to access your site, and many will block the connection entirely. Your site will not be hacked or deleted, but visitors will see a message saying the site is unsafe. Renew the certificate immediately to restore normal access. This is why automatic renewal is important.
Do I need a different certificate for each domain I own?
Yes, each domain needs its own certificate. However, a wildcard certificate covers one domain and all its subdomains (like example.com, mail.example.com, and blog.example.com). A multi-domain certificate covers multiple unrelated domains with one certificate. Both cost more than a single-domain certificate but are cheaper than buying separate certificates for each domain.
Is a free SSL certificate as secure as a paid one?
Yes. A free Let's Encrypt certificate encrypts data just as strongly as a paid certificate from DigiCert or Sectigo. Browsers trust them equally. The difference is not security — it is verification level. A paid OV or EV certificate proves your organization is real, while a free DV certificate only proves you own the domain. For encryption strength, they are identical.
Can I get an SSL certificate for an IP address instead of a domain name?
Most certificate authorities do not issue certificates for IP addresses because they are designed for domain names. If you need to access your site by IP address, you will need a dedicated server with a domain name and certificate. For most situations, using a domain name is simpler and more secure.