What you need to do to get an HTTPS certificate
An HTTPS certificate (also called an SSL/TLS certificate) is a file you install on your web server that encrypts traffic between your site and visitors' browsers. To get one, you choose a certificate provider, prove you own or control the domain, and install the certificate on your hosting account. Most hosting providers offer free certificates through Let's Encrypt, a nonprofit that issues them at no cost. If your host doesn't, you can buy a certificate from a commercial provider like Sectigo, DigiCert, or GoDaddy, which typically costs $50 to $200 per year.
The process takes anywhere from a few minutes (if your host automates it) to a few hours (if you install it manually). The hard part is usually proving domain ownership, which the certificate provider requires before issuing the certificate. After that, installation is straightforward on most hosting platforms.
Key Takeaways
- Most hosting providers include free HTTPS certificates through Let's Encrypt, so check your host's control panel before paying for one.
- You will need to prove you own or control the domain by responding to an email, adding a DNS record, or uploading a file to your server.
- Free certificates from Let's Encrypt expire every 90 days but renew automatically on most hosting platforms.
- Commercial certificates cost $50 to $200 per year and last one to three years, but offer no security advantage over free certificates for most websites.
Free certificates through your hosting provider
If you host your site with a major provider like Bluehost, SiteGround, Kinsta, or WP Engine, your control panel almost certainly has a one-click option to install a free HTTPS certificate. Log into your hosting account, look for a section called "SSL/TLS", "Security", or "Certificates", and click the button to install or enable the certificate. The system will handle domain verification and installation automatically, usually within minutes.
These free certificates come from Let's Encrypt and renew automatically every 90 days. You do not need to do anything after the initial setup — your host manages the renewal in the background. If your host does not show an SSL option in the control panel, contact their support team and ask whether they offer free HTTPS certificates. Most do.
Getting a free certificate directly from Let's Encrypt
If your hosting provider does not offer automatic certificate installation, you can get a free certificate directly from Let's Encrypt using a tool called Certbot. Certbot is software that runs on your server and handles both the certificate request and installation. You connect to your server via SSH (a command-line interface), download Certbot, run a few commands, and the certificate is installed and configured.
This route requires some technical comfort with the command line. If that is not you, ask your hosting provider's support team whether they can run Certbot for you, or whether they have a different free option. Many smaller hosts will do this as part of their support service.
Buying a commercial certificate
Commercial certificates from providers like Sectigo, DigiCert, Comodo, or GoDaddy cost $50 to $200 per year and last one to three years. They offer no additional security compared to free Let's Encrypt certificates — both encrypt traffic equally well. The main reasons to buy one are: your host does not offer free certificates and you cannot install Certbot yourself, or you want an extended validation (EV) certificate that displays your company name in the browser address bar.
To buy a certificate, choose a provider, select the certificate type and duration, and complete the purchase. You will then follow the provider's process to prove domain ownership (usually by email confirmation or DNS record) and download the certificate files. Your hosting provider's support team can install these files on your server if you are not comfortable doing it yourself.
Proving you own the domain
Before any certificate provider issues a certificate, they must verify that you own or control the domain. They offer three main methods: email verification, DNS record verification, or file upload verification. Email verification is the simplest — the provider sends a confirmation email to an address associated with the domain (like admin@yourdomain.com), and you click a link to confirm. This usually takes a few minutes.
DNS verification requires you to add a temporary record to your domain's DNS settings. This is slightly more technical but works even if you cannot receive email at the domain. File upload verification requires you to upload a small text file to a specific folder on your web server. All three methods are secure; choose whichever your certificate provider offers and you feel most comfortable with.
Installing the certificate on your server
If your hosting provider automates certificate installation (which most do), you have nothing to do after domain verification — the certificate is already live. If you are installing manually or using a commercial certificate, you will receive certificate files (usually named something like certificate.crt and private.key) that you upload to your server through your hosting control panel or via SSH.
Most hosting control panels have a dedicated section for uploading certificates. Paste the certificate file contents into the appropriate field, paste the private key into another field, and save. Your host's documentation or support team can walk you through the exact steps for your platform. After installation, your site should show a padlock icon in the browser address bar within a few minutes.
Renewing your certificate before it expires
Free Let's Encrypt certificates expire every 90 days, but most hosting providers renew them automatically without any action from you. Check your hosting control panel occasionally to confirm the certificate is still active — you should see a date showing when it expires. If your host does not automate renewal, you will receive an email reminder before expiration. Request a new certificate through the same process you used to get the first one.
Commercial certificates last longer (one to three years) and you will receive renewal reminders from the certificate provider before expiration. Renewing is usually as simple as logging into your provider's account, clicking "renew", and completing domain verification again. Your host can install the renewed certificate the same way they installed the original.
Frequently Asked Questions
Do I need a different certificate for each subdomain?
No. A standard certificate covers your main domain and all subdomains (like blog.yourdomain.com and shop.yourdomain.com). If you need to cover multiple unrelated domains, you can buy a wildcard certificate or a multi-domain certificate, but most sites need only one standard certificate.
What happens if my certificate expires?
Browsers will show a security warning and visitors may not be able to reach your site. Renewal is usually automatic on modern hosting platforms, but if it fails, contact your host immediately. They can issue a new certificate and install it within hours.
Can I move a certificate to a different hosting provider?
Free Let's Encrypt certificates are tied to your domain, not your host, so you can request a new one on your new host immediately. Commercial certificates are usually tied to a specific domain and can be transferred, but you may need to contact the certificate provider to reissue it for your new server.
Is a paid certificate more secure than a free one?
No. Both free and paid certificates use the same encryption technology and protect your visitors' data equally well. The difference is in features like longer validity periods or a company name displayed in the browser — not in security.
What if I cannot prove domain ownership?
Contact your domain registrar (the company where you bought the domain) and ask them to update the domain's contact email or DNS settings so you can receive verification emails or add DNS records. If you no longer have access to the domain, you may need to prove ownership through other means — ask the certificate provider what options exist.