Putting an ASP.NET site on HTTPS takes two parts: a certificate installed in Plesk, and an application that behaves correctly once it is served over HTTPS. Every Domain India Windows plan includes a free Let's Encrypt certificate, so the Plesk part takes a few clicks. This tutorial covers both parts, with the ASP.NET settings that most often cause padlock warnings, redirect loops or insecure cookies.
In Plesk, install the free Let's Encrypt certificate from SSL/TLS Certificates for your domain, including www, webmail and mail, and turn on the 301 redirect from HTTP to HTTPS. Then check your app: redirect in one place only, add HSTS once everything works, mark cookies as Secure, and remove any http:// links to images and scripts. The domain must point at your hosting before the certificate can be issued.
Certificate installation, renewal and third-party certificates are covered step by step in Installing SSL in Plesk. The redirect options are in HTTPS redirect in Plesk.
1. What you need first
- The domain pointing at your Windows hosting. Let's Encrypt checks your site over port 80 before issuing. See How do I change my nameservers.
- Plesk access. Open your hosting services in the client area and click the Plesk button on your domain's row.
- Your app deployed and working over
http://, so you can tell SSL problems apart from app problems.
2. Install the free certificate
- Open SSL/TLS Certificatesfor your domain under Websites & Domains.
- Choose Let's Encryptand enter an email address for expiry notices.
- Tick the domain,
www, webmail and mailif they are offered, so every address you use is covered. - Install, then open
https://yourdomain.comin a private window and check the padlock.
Plesk renews Let's Encrypt certificates automatically while the domain still points at your hosting. If you need a certificate from another provider, Plesk accepts uploaded certificates too; the canonical guide explains how, and support can help if you are unsure.
3. Choose one place to redirect HTTP to HTTPS
You can force HTTPS in three places. Pick one:
| Where | How | Best for |
|---|---|---|
| Plesk | Hosting Settings, tick Permanent SEO-safe 301 redirect from HTTP to HTTPS | Most sites; no code changes |
| web.config | A URL Rewrite rule, as in the redirect guide | Combining HTTPS with a www or non-www rule |
| ASP.NET Core code | app.UseHttpsRedirection() in Program.cs | Apps that must enforce HTTPS themselves |
Using more than one is the usual cause of redirect trouble. If you tick the Plesk option, you can remove UseHttpsRedirection() or leave it; the request already arrives on HTTPS. Don't add a web.config rule as well.
4. Add HSTS once everything works
HTTP Strict Transport Security tells browsers to use HTTPS for your domain for a set time, even if someone types http://. In ASP.NET Core it is one line, and the default templates already include it for production:
if (!app.Environment.IsDevelopment())
{
app.UseHsts();
}Turn it on only after HTTPS works for every address you use, including www. Browsers remember HSTS, so a mistake can't be undone quickly. Avoid the preload option unless you are sure every subdomain will always have HTTPS.
5. Protect cookies
Login and session cookies must never travel over plain HTTP.
ASP.NET Core:
builder.Services.ConfigureApplicationCookie(o =>
{
o.Cookie.SecurePolicy = CookieSecurePolicy.Always;
o.Cookie.HttpOnly = true;
});.NET Framework: in web.config, set requireSSL="true" on the httpCookies element under system.web, and on the forms element if you use forms authentication.
6. Fix mixed content
If the padlock is missing or shows a warning on some pages, the page loads something over http://:
- search your views, layouts and CSS for
http://and change the links tohttps://, or to relative paths; - check URLs stored in your database, such as image paths saved by an editor;
- check third-party scripts and fonts, which must also load over HTTPS.
The browser console lists each blocked or insecure item.
7. Test the result
- Open
http://yourdomain.comandhttp://www.yourdomain.com: each should end onhttps://in one redirect. - Log in and check, in the browser's developer tools, that your cookies are marked Secure.
- Use an online SSL checker to confirm the certificate chain and name coverage.
If Let's Encrypt fails to install, or the browser still warns after installation, see the troubleshooting table in Installing SSL in Plesk.
8. Where Domain India Windows hosting fits
Every Windows plan includes free SSL through Let's Encrypt, managed in Plesk. The cards show live prices, excluding 18% GST.
- 10 GB Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
- 30 GB Storage
- 150 GB Monthly Bandwidth
- 5 Websites
- 50 Email Accounts
New shared hosting purchases, Windows included, can be refunded in full within 30 days under our refund policy. For protecting the data your app sends to databases, mail servers and APIs, see Securing data transmissions with HTTPS in ASP.NET.
Is SSL free on Domain India Windows hosting?
Yes. Every Windows plan includes a free Let's Encrypt certificate, which you install in Plesk under SSL/TLS Certificates and which Plesk renews automatically while the domain points at your hosting.
Why won't Let's Encrypt install for my ASP.NET site?
Usually because the domain or its www version doesn't point at your hosting yet, so the check over port 80 fails. Fix the DNS, wait for it to update, and try again.
Should I use UseHttpsRedirection or the Plesk redirect?
Use one. The Plesk option, Permanent SEO-safe 301 redirect from HTTP to HTTPS, works for most sites without code changes. Don't add a web.config rewrite rule as well.
When should I enable HSTS?
Only after HTTPS works for every address your site uses, including www. Browsers remember HSTS, so turning it on too early can lock visitors out of an address without a certificate.
Why is the padlock missing on some pages?
Those pages load images, scripts or fonts over http. Change the links to https or relative paths, including URLs stored in your database.
Ready to secure your ASP.NET site? Compare the Windows hosting plans, or open a ticket if the certificate won't install. Support is on 24/7 live chat, and tickets get a first response within 15 minutes.
Let's Encrypt certificates installed and renewed in Plesk, at no extra cost.
See Windows hosting plans