What you need to do to get HTTPS working

To get an HTTPS certificate, you request one from a Certificate Authority — an organization that issues and verifies these certificates. The process differs depending on whether you host your own server or use a hosting provider. If you use a hosting platform like Squarespace, Wix, or WordPress.com, HTTPS is usually already turned on and you do not need to do anything. If you manage your own server or use a hosting provider that does not include it, you will need to request a certificate, prove you own the domain, and install it on your server.

The fastest and cheapest route for most people is Let's Encrypt, a free Certificate Authority that automates most of the work. If you use a hosting control panel like cPanel or Plesk, there is usually a one-click button to request a Let's Encrypt certificate. If you manage a server directly, you use a tool called Certbot to request and install the certificate automatically. The whole process takes minutes once you have access to your server or hosting control panel.

Key Takeaways

  • Most hosting platforms (Squarespace, Wix, WordPress.com, Shopify) include HTTPS automatically — you do not need to request a certificate yourself.
  • If your hosting provider has a control panel like cPanel or Plesk, look for an "SSL Certificate" or "Let's Encrypt" button to request a free certificate with one click.
  • Let's Encrypt is free and works with almost all hosting setups, but the certificate expires every 90 days and must be renewed automatically or manually.
  • If you manage a server directly, use Certbot to request and install a Let's Encrypt certificate from the command line.
  • Paid certificates from providers like Comodo or DigiCert offer longer validity periods and more support, but are not necessary for most websites.

Check whether your hosting provider already includes HTTPS

Before you request a certificate, confirm whether your host already provides one. Log into your hosting account and look for a settings page labeled "SSL", "Security", "Certificates", or "HTTPS". If you see a certificate already listed, or if there is a toggle to turn HTTPS on, your host has already set it up for you. You may just need to enable it.

If you use a website builder like Squarespace, Wix, WordPress.com, or Shopify, HTTPS is included and active by default. You do not need to request or install anything. If you are unsure whether your host includes HTTPS, contact their support team directly — they can tell you in one message whether a certificate is already in place.

Request a free certificate through your hosting control panel

If your hosting provider uses cPanel, Plesk, or another control panel, look for an SSL or certificate section. In cPanel, this is usually under "Security" and labeled "AutoSSL" or "Let's Encrypt". Click the button to request a certificate. The system will automatically verify that you own the domain and install the certificate on your server. This usually takes a few minutes.

If you see an option for "AutoSSL", enable it. This automatically renews your Let's Encrypt certificate every 90 days so you do not have to remember to do it manually. After the certificate is installed, your site will be accessible over HTTPS (you will see the padlock icon in the browser address bar). If the button is not there, your hosting provider may not support Let's Encrypt, and you will need to contact their support team or use the command-line method below.

Install a certificate on a server you manage directly

If you manage your own server or have root access, use Certbot to request and install a Let's Encrypt certificate. Certbot is a free tool that automates the entire process. The steps depend on your operating system and web server software (Apache, Nginx, or another).

On a Linux server running Apache or Nginx, open a terminal and run the Certbot installation command for your setup. Certbot will ask you to confirm your domain name, verify that you own it by checking your DNS records or by placing a file on your server, and then automatically install the certificate. After installation, Certbot sets up automatic renewal so your certificate stays valid. The official Certbot website (certbot.eff.org) has step-by-step instructions for every combination of operating system and web server.

If you are not comfortable using the command line, ask your hosting provider whether they offer a managed certificate service, or hire a system administrator to set it up for you. The cost is usually low because Let's Encrypt certificates are free — you are only paying for the time to install it.

Understand Let's Encrypt certificates versus paid certificates

Let's Encrypt certificates are free and work exactly the same way as paid certificates from other providers — they encrypt traffic between your visitor's browser and your server, and they prove you own the domain. The only real difference is that Let's Encrypt certificates expire every 90 days and must be renewed. If you set up automatic renewal (which most hosting panels and Certbot do by default), you will never notice the expiration because it happens in the background.

Paid certificates from providers like Comodo, DigiCert, or Sectigo last one to three years before expiring, so you renew less often. Some paid certificates also include an "Extended Validation" badge that displays your company name in the browser, which can build trust for e-commerce sites. For most websites — blogs, small business sites, portfolios — a Let's Encrypt certificate is sufficient and saves you money. Paid certificates make sense if you want longer validity periods or the trust badge, but they are not required for security.

Verify that HTTPS is working

After your certificate is installed, visit your website in a browser and look at the address bar. You should see a padlock icon next to your domain name. Click the padlock to view certificate details and confirm the certificate is valid. If you see a warning or error instead, the certificate may not have installed correctly, or it may not cover all the domains you use (for example, if your site is accessible at both www.example.com and example.com, the certificate must cover both).

If HTTPS is not working, check that your hosting control panel shows the certificate as active, or run Certbot again to verify installation. If your site still shows an error, contact your hosting provider's support team with a screenshot of the error message. They can check the server logs to see what went wrong.

Renew your certificate before it expires

Let's Encrypt certificates expire 90 days after they are issued. If you set up automatic renewal through your hosting control panel or Certbot, the certificate will renew automatically and you do not need to do anything. To confirm automatic renewal is working, check your hosting control panel or run the command certbot renew --dry-run on your server to test the renewal process.

If automatic renewal is not set up, you will receive email warnings as the expiration date approaches. When you see the warning, log into your hosting control panel and click the renewal button, or run Certbot again to renew manually. If you let the certificate expire without renewing, visitors will see a security warning and may not trust your site. Paid certificates last longer (one to three years), so you renew less frequently, but they cost money and are not necessary unless you prefer the longer validity period.

Frequently Asked Questions

Do I need a paid certificate or is Let's Encrypt enough?

Let's Encrypt is enough for almost all websites. It encrypts traffic just as well as paid certificates and proves you own the domain. The only reason to buy a paid certificate is if you want a longer validity period (so you renew less often) or an Extended Validation badge that displays your company name in the browser.

What happens if my certificate expires?

Visitors will see a security warning in their browser and may leave your site. If you set up automatic renewal, this will not happen because the certificate renews before it expires. If you did not set up automatic renewal, you will receive email warnings before expiration — renew immediately when you see the warning.

Can I use one certificate for multiple domains?

Yes, with a wildcard certificate or a multi-domain certificate. A wildcard certificate covers a domain and all its subdomains (example.com, www.example.com, mail.example.com). A multi-domain certificate covers several unrelated domains in one certificate. Let's Encrypt supports both, and most hosting control panels let you select which domains to cover when you request the certificate.

Why does my site still show HTTP instead of HTTPS after I installed the certificate?

Your site may have links or resources (images, stylesheets, scripts) that load over HTTP instead of HTTPS. Browsers will not show the padlock if any part of the page loads insecurely. Search your website code for "http://" links and change them to "https://" or remove the protocol entirely so the browser uses whatever protocol the page uses. Your hosting provider's support team can help you find and fix these mixed-content errors.

Can I move my certificate to a different hosting provider?

Let's Encrypt certificates are tied to your domain, not to a specific hosting provider. When you move to a new host, request a new Let's Encrypt certificate through your new host's control panel or Certbot. The process is the same as the first time. You do not need to export or transfer the old certificate — just request a new one on the new server.