What an SSL certificate does and where to get one
An SSL certificate is a file you install on your web server that encrypts the connection between your website and the people visiting it. When someone sees the padlock icon in their browser's address bar, that padlock means an SSL certificate is doing its job — scrambling the data so it cannot be read if intercepted.
You obtain an SSL certificate from a Certificate Authority (CA) — a company that verifies you own the domain and issues the certificate. Common CAs include Let's Encrypt (free), Sectigo, DigiCert, and GoDaddy. The process takes anywhere from minutes to a few days depending on which CA you choose and what type of certificate you need.
Most web hosting providers let you install an SSL certificate through their control panel, often with a single click. If you manage your own server, you will download the certificate files and install them manually using your server software (Apache, Nginx, or IIS, depending on your setup).
Key Takeaways
- Let's Encrypt offers free SSL certificates and renews them automatically, making it the lowest-cost option for most websites.
- You must prove you own or control the domain before any Certificate Authority will issue a certificate, usually by adding a DNS record or uploading a file to your server.
- Most web hosting control panels include a one-click SSL installation tool that handles the technical steps for you.
- SSL certificates expire and must be renewed, typically every one to three years depending on the certificate type.
- A basic Domain Validated (DV) certificate costs nothing to hundreds of dollars per year; Organization Validated (OV) and Extended Validation (EV) certificates cost more but show more information to visitors.
The three types of SSL certificates and what they cost
Domain Validated (DV) certificates verify only that you own the domain. They are the fastest and cheapest option — Let's Encrypt issues them free, and commercial CAs charge $10 to $50 per year. A visitor sees the padlock but no company name in the certificate details.
Organization Validated (OV) certificates verify that you own the domain and that your organization is real and registered. The CA checks your business registration and may call to confirm. These cost $100 to $300 per year and show your company name when a visitor clicks the padlock.
Extended Validation (EV) certificates require the most thorough verification — the CA confirms your legal identity, ownership, and operational control. Browsers sometimes display the company name directly in the address bar (though this has become less common). EV certificates cost $200 to $500 per year and are mainly used by banks, payment processors, and large retailers.
For most websites — blogs, small businesses, portfolios — a DV certificate is sufficient. The encryption is identical across all three types. The difference is what the certificate proves about who you are.
How to prove you own your domain
Before a Certificate Authority issues a certificate, you must prove you control the domain. The CA offers three common methods: DNS validation, HTTP validation, or email validation.
DNS validation requires you to add a special DNS record (usually a CNAME or TXT record) to your domain's DNS settings. You log into your domain registrar (GoDaddy, Namecheap, Google Domains, etc.), find the DNS management section, and add the record the CA provides. The CA checks for this record within minutes to a few hours. This method works even if your website is not yet live.
HTTP validation requires you to upload a small text file to a specific folder on your web server (usually `.well-known/acme-challenge/`). The CA fetches this file to confirm you control the server. This method is fast but requires your website to be live and accessible.
Email validation sends a confirmation link to an email address associated with the domain (like admin@yourdomain.com or the registrant email on file). You click the link to prove you received the email. This is the slowest method and requires that email to be set up and monitored.
If you use a web hosting provider with a one-click SSL tool, the provider usually handles validation automatically — you do not see these steps.
Installing an SSL certificate on your hosting account
If your web host offers a control panel (cPanel, Plesk, or the host's custom panel), look for an SSL or Security section. Most panels include a tool called "AutoSSL" or "Free SSL" that installs a Let's Encrypt certificate with one click. The tool requests the certificate, validates your domain automatically, and installs it on your website — all without you touching the command line.
To use this tool, navigate to the SSL section, select your domain, and click the button to install. The process usually completes within minutes. Once installed, your website will be accessible at both http://yourdomain.com and https://yourdomain.com, though you should redirect all traffic to the HTTPS version.
If you manage your own server or your host does not offer automated installation, you will download certificate files from the CA and install them manually. This involves editing your server configuration file (for Apache, usually `httpd.conf` or a file in `sites-available/`; for Nginx, usually `nginx.conf`). You specify the path to three files: the certificate, the private key, and the certificate chain. After saving the configuration and restarting the server, the certificate is live.
If you are unfamiliar with server configuration, ask your hosting provider's support team to install the certificate for you — most will do this at no extra cost.
Renewing your SSL certificate before it expires
SSL certificates expire — typically after one, two, or three years depending on the type and CA. If you do not renew before expiration, visitors will see a security warning and browsers may block access to your site.
Let's Encrypt certificates expire after 90 days but renew automatically if you use their recommended tools (Certbot, or your hosting provider's AutoSSL). You do not need to do anything; the renewal happens in the background.
Paid certificates from commercial CAs expire after one to three years. Most CAs send email reminders 30 to 60 days before expiration. You log into your CA account, pay the renewal fee, and request a new certificate. The CA may ask you to re-validate your domain (usually via DNS or HTTP again). Once the new certificate arrives, you install it the same way you installed the first one.
If your hosting provider manages SSL for you, renewal is usually automatic — the provider renews on your behalf and installs the new certificate without interruption.
Redirecting HTTP traffic to HTTPS
Installing an SSL certificate makes HTTPS available, but it does not automatically force visitors to use it. Someone typing http://yourdomain.com will still reach your site unencrypted unless you set up a redirect.
In most hosting control panels, you can set this redirect in a few clicks. Look for an option called "Force HTTPS" or "Redirect HTTP to HTTPS" in the SSL or Domain settings. If your host does not offer this, you can add a redirect rule to your site's configuration file or use a plugin if your site runs WordPress.
For WordPress, install a plugin like Really Simple SSL or All in One WP Security, which handles the redirect and updates internal links automatically. For other platforms, add a redirect rule to your `.htaccess` file (Apache) or `nginx.conf` (Nginx), or configure it in your application code.
Troubleshooting common SSL certificate problems
If your browser shows a security warning after you install a certificate, the most common cause is a mismatch between the domain in the certificate and the domain in the address bar. For example, if your certificate is for www.yourdomain.com but visitors access yourdomain.com (without www), the certificate will not match. Request a new certificate that covers both versions, or set up a redirect so all traffic goes to the version the certificate covers.
Another common issue is an expired intermediate certificate. Your certificate chain includes not just your certificate but also the CA's intermediate certificate. If the intermediate has expired, browsers will show a warning even if your certificate is valid. Most CAs update their intermediates automatically, but if you installed the certificate manually, check that you included the full chain.
If the certificate installed but the site still shows as insecure, clear your browser cache and try a different browser. Sometimes cached data causes the warning to persist even after the certificate is live. If the warning appears in multiple browsers, check that you redirected HTTP to HTTPS and that all resources on your page (images, scripts, stylesheets) load over HTTPS, not HTTP. A single unencrypted resource will trigger a "mixed content" warning.
Frequently Asked Questions
Do I need an SSL certificate if my website does not collect passwords or payment information?
Yes. Google and other search engines rank encrypted sites higher, and browsers display warnings on unencrypted sites. Even a simple blog benefits from SSL. More importantly, any site that collects email addresses, contact forms, or login credentials should use SSL to protect that data.
Can I use the same SSL certificate on multiple domains?
Not with a standard certificate. A basic DV or OV certificate covers one domain (or one domain plus www). If you need to cover multiple unrelated domains, you can purchase a wildcard certificate (covers all subdomains of one domain, like mail.yourdomain.com and blog.yourdomain.com) or a multi-domain certificate (covers several different domains). These cost more than a single-domain certificate.
What happens if my SSL certificate expires?
Visitors will see a security warning and many browsers will block access to your site. Search engines may also penalize the site. If you use Let's Encrypt with automatic renewal, expiration is nearly impossible. If you use a paid certificate, set a calendar reminder 30 days before expiration so you have time to renew.
Can I move an SSL certificate to a different hosting provider?
Let's Encrypt certificates can be re-issued on any server at no cost. Paid certificates are tied to the domain, not the server, so you can request a reissue from the CA and install it on your new host. Some CAs charge a small fee for reissues; check your CA's policy.
Is a free SSL certificate as secure as a paid one?
Yes. The encryption strength is identical. The only difference is what the certificate proves about your identity. A free Let's Encrypt certificate proves you own the domain; a paid EV certificate proves your legal identity as well. For security purposes, both are equally strong.