Installing on DirectAdmin

How to Enable Let's Encrypt SSL Certificates in DirectAdmin

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (8 sections)

A free Let's Encrypt certificate puts your site on https://, removes the browser's "Not secure" warning and renews itself. On Domain India's DirectAdmin hosting there is nothing to request: DirectAdmin issues the certificate by itself once your domain points at your hosting, and renews it by itself. This guide shows how to check that the certificate was issued, and how to fix the usual reasons it is not.

Key takeaways

Point your domain's A record (or nameservers) to your DirectAdmin hosting and wait. DirectAdmin then issues a free Let's Encrypt certificate automatically and renews it well before it expires; there is no request form to fill in. To confirm, open Account Manager › SSL/TLS Certificates in DirectAdmin and look at the certificate list. If a name is listed under Automatic certificate provisioning as failed, fix its DNS and wait for DirectAdmin to retry; if it still fails, ask support.

1. What Let's Encrypt gives you

Let's Encrypt is a free, automated certificate authority trusted by every modern browser. Its certificates:

  • encrypt traffic between visitors and your site, so logins and form data cannot be read in transit;
  • are domain validated: they prove you control the domain, not who your company is;
  • are short-lived (90 days or less) and designed to be renewed automatically, which DirectAdmin does for you.

For almost every website, blog, shop or business site, a Let's Encrypt certificate is all you need. If you need a paid certificate for a specific reason, ask support, or upload a certificate you bought elsewhere; see How to install an SSL certificate in DirectAdmin.

2. What is already set up on our DirectAdmin server

Read on our DirectAdmin server on 30 September 2026, on the ACME settings tab of the SSL/TLS Certificates page:

SettingValue on our serverWhat it means for you
Enable ACMETicked by defaultDirectAdmin issues and renews your domain's certificates automatically
ACME providerDefault (Let's Encrypt)The certificate is free
Key typeECDSA P-256 by defaultNothing to choose
Prefer wildcard certificatesTicked by defaultWhere possible, one wildcard certificate covers the domain and its subdomains; otherwise a certificate with the exact names is issued
Names DirectAdmin triesThe domain, www, mail, ftp, pop and smtpA name gets a certificate only if it reaches our server
RenewalAutomatic, well before the certificate expiresYou don't need to renew by hand
DirectAdmin ACME settings tab: Enable ACME ticked, Key type ECDSA P-256, Prefer wildcard certificates ticked, and ACME provider set to Default (Let's Encrypt)
ACME settings: automatic certificates are on by default.

SSL is enabled for almost every account. If your account is one of the few with SSL off, or the SSL/TLS Certificates page is not shown, open a ticket and we will switch it on.

3. First, check your DNS

Let's Encrypt checks that your domain really points to the server asking for the certificate. It does this by fetching a small file over plain http:// on port 80. DirectAdmin cannot get a certificate for a name if:

  • the domain's A record still points to your old host, or DNS changes have not spread yet;
  • the name has no DNS record at all, for example www with no A or CNAME record;
  • a proxy or CDN in front of the site (for example a proxied Cloudflare record) answers instead of our server;
  • a CAA record on the domain allows only another certificate authority.

To point the domain at your hosting, use the nameservers or the server IP from the Access tab of your hosting service in the client area. See How do I change my nameservers. The certificate can be issued once the domain opens your DirectAdmin site over http://.

4. Check that the certificate was issued

  1. Point the domain at your hosting.
    Set the nameservers or the A record as described in section 3.
  2. Wait.
    There is nothing to request. Once the domain reaches our server, DirectAdmin issues the certificate on its own. DNS changes can take a while to spread first.
  3. Open DirectAdmin.
    In the client area, open your hosting services, select your DirectAdmin service and open the control panel from there.
  4. Open Account Manager › SSL/TLS Certificates.
    The page has three tabs: Manage certificates, ACME settings and Provisioning history.
  5. Read the Certificate list
    on the Manage certificates tab. Each certificate is shown with its DNS names, validity, expiry date and renewal mode. Your domain should be among the DNS names.
  6. Look for names that were left out.
    A name that has no certificate appears under DNS names without TLS certificate, and a name DirectAdmin tried and could not secure appears under Automatic certificate provisioning with the reason. Section 6 explains what to do.

You can also check from outside: open https://yourdomain.com and click the padlock. The certificate should be issued by Let's Encrypt.

5. Send every visitor to HTTPS

A certificate does not move visitors to https:// on its own. Two ways to do it:

  • DirectAdmin's own setting. Many versions have a "Force SSL with https redirect" option in the domain's settings. Turn it on if your panel shows it.
  • .htaccess. The server runs Apache with mod_rewrite, so this rule in the .htaccess file in public_html works:
apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Use one method, not both. For more rewrite rules, see How to enable the mod_rewrite module.

For WordPress, also change Settings › General › WordPress Address and Site Address to https://. If the padlock still shows a warning, the page loads images or scripts over http:// (mixed content); update those links, or run a search-and-replace on your database.

6. If a name is listed as failed

When DirectAdmin cannot issue a certificate for a name, the Manage certificates tab says so under Automatic certificate provisioning, with the reason. The most common one is Failed HTTP checks: DirectAdmin explains that the names listed cannot get automatic certificates because an HTTP request for them does not reach the server, which happens when the names have no DNS records or the records point to a different server.

DirectAdmin Manage certificates page: an empty certificate list, a DNS names without TLS certificate list, and an Automatic certificate provisioning box listing failed HTTP checks for names that do not reach the server
Manage certificates shows each certificate and, when automatic issuing fails, the reason.
What you seeLikely causeFix
Your domain under failed HTTP checksThe domain points elsewhere, or a proxy answersPoint the A record to our server, turn off the proxy, wait for DNS
Wrong content is fetched by the checkAn old host or a redirect answers the checkRemove redirects that send the check file elsewhere; check the A record
Only www, mail or another name is listedThat name has no DNS record, or its record points to another serverAdd a record pointing to your hosting if you want the name covered; otherwise you can leave it
CAA errorA CAA record allows only another authorityAdd letsencrypt.org to the CAA record, or remove it
Nothing is issued even after DNS is rightAutomatic issuing may have been switched off for the domain after repeated failuresOpen the ACME settings tab and check that Enable ACME is still ticked

After you fix the cause, wait: DirectAdmin retries on its own, and you do not need to submit anything. The Provisioning history tab is the place to look for past attempts. If the name still fails, open a ticket with the domain name and the reason DirectAdmin shows.

Don't block the validation path

Let's Encrypt fetches a file under /.well-known/acme-challenge/. A security plugin, a .htaccess rule that denies dotted folders, or a redirect of all traffic to another domain can break both the first certificate and later renewals.

7. Renewal and wildcard certificates

DirectAdmin renews Let's Encrypt certificates automatically, well before they expire, using the same kind of check as the first time. Renewal fails for the same reasons: if you move DNS to a proxy or another host, the next renewal breaks. The Expires column in the certificate list shows the current expiry date, so you can confirm a renewal happened.

A wildcard certificate (*.yourdomain.com) is not something you request either. Prefer wildcard certificates is ticked by default on the ACME settings tab: if a single wildcard certificate can be issued to cover the domain and its subdomains, DirectAdmin issues one; if it cannot, DirectAdmin issues a certificate with the exact names instead. A wildcard needs DNS validation rather than the file check, which depends on where your DNS is hosted, so seeing exact names in the certificate list is normal and works just as well.

8. Where Domain India hosting fits

Every Domain India shared hosting plan includes free SSL: AutoSSL with Let's Encrypt on cPanel, and Let's Encrypt in DirectAdmin. DirectAdmin plans also include weekly backups with JetBackup. Compare plans and live prices on DirectAdmin hosting.

If you are on cPanel instead, see AutoSSL in cPanel.

Is the Let's Encrypt SSL certificate free on Domain India DirectAdmin hosting?

Yes. The certificate costs nothing, and you do not have to request it. DirectAdmin issues a Let's Encrypt certificate automatically once your domain points at your hosting, and renews it automatically.

How long does a Let's Encrypt certificate last?

Let's Encrypt certificates are short-lived, 90 days or less, and are meant to be renewed automatically. DirectAdmin renews them well before they expire, so you don't need to do anything while your domain keeps pointing to the server.

Where do I see my SSL certificate in DirectAdmin?

Open Account Manager › SSL/TLS Certificates. The Manage certificates tab lists each certificate with its DNS names, validity and expiry date, and lists any names that could not get a certificate along with the reason.

Why has DirectAdmin not issued a Let's Encrypt certificate for my domain?

Usually because the domain or www does not yet point to the DirectAdmin server, a proxy or CDN answers instead, or a CAA record allows only another certificate authority. Fix the DNS and wait; DirectAdmin retries on its own. If it still fails, open a support ticket with the domain name.

Do I need to include www in the certificate?

You do not choose the names. DirectAdmin tries the domain, www, mail, ftp, pop and smtp by default, and a name gets a certificate only if it reaches the server. For www to be covered, give it a DNS record that points to your hosting.

How do I force HTTPS once the certificate is in place?

Turn on DirectAdmin's HTTPS redirect option if your panel shows it, or add a RewriteRule to the .htaccess file in public_html that redirects http to https with a 301. Use one method only.

Can I get a wildcard certificate in DirectAdmin?

DirectAdmin decides this by itself. Prefer wildcard certificates is ticked by default, so a single wildcard certificate is issued when that is possible; when it is not, DirectAdmin issues a certificate with the exact names instead.

Ready to secure your site? Check that your domain points to your hosting with How do I change my nameservers, then open your hosting services to reach DirectAdmin, or compare DirectAdmin hosting plans.

Certificate still not issued?

Send us the domain and the reason DirectAdmin shows under Automatic certificate provisioning, and we will check the DNS and the certificate with you.

Open a support ticket

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Enable Free Let's Encrypt SSL in DirectAdmin