How to Install a Free SSL Certificate in cPanel
Get HTTPS working with a free certificate in cPanel, through AutoSSL or a Let's Encrypt integration, check that it covers www and subdomains, and fix the most common validation failures.

Table of Contents
- Before you start
- Step 1: Check the current status
- Step 2: Run AutoSSL
- Step 3: Make sure every name is covered
- Step 4: Redirect to HTTPS
- Step 5: Verify
- Fixing common validation failures
- Worked example: a new site with www not covered
- Checking certificate details from the command line
- Renewal
- Frequently Asked Questions
- Related reading
- Sources
Most cPanel servers issue free SSL certificates automatically through AutoSSL (using a provider such as Let's Encrypt or Sectigo, depending on the server's configuration). Once your domain points to the hosting server, open SSL/TLS Status in cPanel, check that your domain and www are covered, and click Run AutoSSL if a certificate is missing. Certificates then renew automatically, which matters more than ever as certificate lifetimes shrink.
Before you start
- The domain (and
www) must resolve to this hosting server. See how to point a domain to hosting. - Wait for DNS propagation after any change; validation fails if the CA sees the old server.
Step 1: Check the current status
- Log in to cPanel and open Security → SSL/TLS Status.
- You will see each domain and subdomain with an icon:
- green/secured: a valid certificate is installed;
- warning or error: no certificate, expired, or validation failed (hover or expand for the reason).
Step 2: Run AutoSSL
Click Run AutoSSL. It may take a few minutes. Refresh the page to see the result. If your host uses a Let's Encrypt plugin instead, open the Let's Encrypt SSL tool (where provided) and issue a certificate for your domain and www.
If neither tool is available, contact your host.
Step 3: Make sure every name is covered
A certificate must include every hostname visitors use:
example.comandwww.example.com;- any subdomains you use (
shop.example.com); mail.or other service subdomains if you connect apps to them.
In SSL/TLS Status, you can choose which names to include or exclude from AutoSSL.
Step 4: Redirect to HTTPS
Installing a certificate does not force visitors onto HTTPS. Set up a redirect and fix mixed content; see how to force HTTPS and fix mixed content.
Step 5: Verify
- Visit
https://yourdomain.comandhttps://www.yourdomain.com; the padlock should appear without warnings. - Click the padlock to check the certificate's names and expiry date.
Fixing common validation failures
| Message or symptom | Cause | Fix |
|---|---|---|
| Domain does not resolve to this server | DNS points elsewhere (or still propagating) | Fix A record or nameservers; wait for propagation |
www not covered |
No DNS record for www |
Add an A or CNAME record for www, then run AutoSSL again |
| Validation via HTTP failed | .htaccess redirects or security rules block the validation path |
Allow requests to /.well-known/ and re-run |
| Behind Cloudflare proxy | The CA cannot reach the origin as expected | Use Full (strict) mode with a valid origin certificate; see how to set up Cloudflare DNS |
| CAA record blocks issuance | Your DNS restricts which CAs may issue | Add the CA your host uses to the CAA record; see DNS record types explained |
| Rate limit reached | Too many issuance attempts | Wait and retry later |
Worked example: a new site with www not covered
You moved example.com to new hosting yesterday. SSL/TLS Status shows example.com secured, but www.example.com shows a red icon with "DNS DCV: The domain does not resolve to this server" (or a similar message). The steps:
- Check DNS:
dig www.example.comreturns no answer, or the old server's IP. Thewwwrecord was never created at the new DNS host. - Add the record: an A record for
wwwpointing to the hosting IP, or a CNAME fromwwwtoexample.com. See how to edit DNS records in cPanel Zone Editor. - Wait for the record to resolve (check with
diguntil it returns the hosting IP). - Click Run AutoSSL again. After a few minutes both names show as secured.
- Visit
https://www.example.comto confirm, then set up the HTTPS and www redirects.
Most AutoSSL failures follow this pattern: a name that does not resolve to the server yet.
Checking certificate details from the command line
To confirm which certificate a server presents and when it expires:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
| openssl x509 -noout -subject -issuer -dates -ext subjectAltName
The output lists the names covered (Subject Alternative Names), the issuer and the validity dates, which is handy for monitoring several sites.
Renewal
Certificates renew automatically before they expire, as long as the domain keeps pointing to the server and validation keeps working. Watch for expiry warnings from cPanel or your monitoring. Certificate validity periods across the industry are being shortened in stages (200 days from March 2026, falling further in 2027 and 2029), which makes reliable automation essential. See what is SSL/TLS and how does HTTPS work.
Frequently Asked Questions
Is a free certificate secure enough for a shop?
Yes. The encryption is the same as paid domain-validated certificates. See types of SSL certificates.
Do I need a dedicated IP for SSL?
No. Modern servers use SNI to serve many certificates on one IP.
Can I install a paid certificate instead?
Yes, in SSL/TLS → Manage SSL sites you can install a certificate you bought, with its private key and CA bundle. Remember you will need to renew it.
Related reading
HTTPS is step 3 of website security basics. Free SSL is included with the ServerNeed shared hosting plans.
Sources
Last updated 7 October 2026



