A free Let's Encrypt certificate puts your site on https://, removes the browser's "Not secure" warning and renews itself. On Domain India's DirectAdmin hosting there is nothing to request: DirectAdmin issues the certificate by itself once your domain points at your hosting, and renews it by itself. This guide shows how to check that the certificate was issued, and how to fix the usual reasons it is not.
Point your domain's A record (or nameservers) to your DirectAdmin hosting and wait. DirectAdmin then issues a free Let's Encrypt certificate automatically and renews it well before it expires; there is no request form to fill in. To confirm, open Account Manager › SSL/TLS Certificates in DirectAdmin and look at the certificate list. If a name is listed under Automatic certificate provisioning as failed, fix its DNS and wait for DirectAdmin to retry; if it still fails, ask support.
1. What Let's Encrypt gives you
Let's Encrypt is a free, automated certificate authority trusted by every modern browser. Its certificates:
- encrypt traffic between visitors and your site, so logins and form data cannot be read in transit;
- are domain validated: they prove you control the domain, not who your company is;
- are short-lived (90 days or less) and designed to be renewed automatically, which DirectAdmin does for you.
For almost every website, blog, shop or business site, a Let's Encrypt certificate is all you need. If you need a paid certificate for a specific reason, ask support, or upload a certificate you bought elsewhere; see How to install an SSL certificate in DirectAdmin.
2. What is already set up on our DirectAdmin server
Read on our DirectAdmin server on 30 September 2026, on the ACME settings tab of the SSL/TLS Certificates page:
| Setting | Value on our server | What it means for you |
|---|---|---|
| Enable ACME | Ticked by default | DirectAdmin issues and renews your domain's certificates automatically |
| ACME provider | Default (Let's Encrypt) | The certificate is free |
| Key type | ECDSA P-256 by default | Nothing to choose |
| Prefer wildcard certificates | Ticked by default | Where possible, one wildcard certificate covers the domain and its subdomains; otherwise a certificate with the exact names is issued |
| Names DirectAdmin tries | The domain, www, mail, ftp, pop and smtp | A name gets a certificate only if it reaches our server |
| Renewal | Automatic, well before the certificate expires | You don't need to renew by hand |

SSL is enabled for almost every account. If your account is one of the few with SSL off, or the SSL/TLS Certificates page is not shown, open a ticket and we will switch it on.
3. First, check your DNS
Let's Encrypt checks that your domain really points to the server asking for the certificate. It does this by fetching a small file over plain http:// on port 80. DirectAdmin cannot get a certificate for a name if:
- the domain's A record still points to your old host, or DNS changes have not spread yet;
- the name has no DNS record at all, for example
wwwwith no A or CNAME record; - a proxy or CDN in front of the site (for example a proxied Cloudflare record) answers instead of our server;
- a CAA record on the domain allows only another certificate authority.
To point the domain at your hosting, use the nameservers or the server IP from the Access tab of your hosting service in the client area. See How do I change my nameservers. The certificate can be issued once the domain opens your DirectAdmin site over http://.
4. Check that the certificate was issued
- Point the domain at your hosting.Set the nameservers or the A record as described in section 3.
- Wait.There is nothing to request. Once the domain reaches our server, DirectAdmin issues the certificate on its own. DNS changes can take a while to spread first.
- Open DirectAdmin.In the client area, open your hosting services, select your DirectAdmin service and open the control panel from there.
- Open Account Manager › SSL/TLS Certificates.The page has three tabs: Manage certificates, ACME settings and Provisioning history.
- Read the Certificate liston the Manage certificates tab. Each certificate is shown with its DNS names, validity, expiry date and renewal mode. Your domain should be among the DNS names.
- Look for names that were left out.A name that has no certificate appears under DNS names without TLS certificate, and a name DirectAdmin tried and could not secure appears under Automatic certificate provisioning with the reason. Section 6 explains what to do.
You can also check from outside: open https://yourdomain.com and click the padlock. The certificate should be issued by Let's Encrypt.
5. Send every visitor to HTTPS
A certificate does not move visitors to https:// on its own. Two ways to do it:
- DirectAdmin's own setting. Many versions have a "Force SSL with https redirect" option in the domain's settings. Turn it on if your panel shows it.
.htaccess. The server runs Apache withmod_rewrite, so this rule in the.htaccessfile inpublic_htmlworks:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]Use one method, not both. For more rewrite rules, see How to enable the mod_rewrite module.
For WordPress, also change Settings › General › WordPress Address and Site Address to https://. If the padlock still shows a warning, the page loads images or scripts over http:// (mixed content); update those links, or run a search-and-replace on your database.
6. If a name is listed as failed
When DirectAdmin cannot issue a certificate for a name, the Manage certificates tab says so under Automatic certificate provisioning, with the reason. The most common one is Failed HTTP checks: DirectAdmin explains that the names listed cannot get automatic certificates because an HTTP request for them does not reach the server, which happens when the names have no DNS records or the records point to a different server.

| What you see | Likely cause | Fix |
|---|---|---|
| Your domain under failed HTTP checks | The domain points elsewhere, or a proxy answers | Point the A record to our server, turn off the proxy, wait for DNS |
| Wrong content is fetched by the check | An old host or a redirect answers the check | Remove redirects that send the check file elsewhere; check the A record |
Only www, mail or another name is listed | That name has no DNS record, or its record points to another server | Add a record pointing to your hosting if you want the name covered; otherwise you can leave it |
| CAA error | A CAA record allows only another authority | Add letsencrypt.org to the CAA record, or remove it |
| Nothing is issued even after DNS is right | Automatic issuing may have been switched off for the domain after repeated failures | Open the ACME settings tab and check that Enable ACME is still ticked |
After you fix the cause, wait: DirectAdmin retries on its own, and you do not need to submit anything. The Provisioning history tab is the place to look for past attempts. If the name still fails, open a ticket with the domain name and the reason DirectAdmin shows.
Let's Encrypt fetches a file under /.well-known/acme-challenge/. A security plugin, a .htaccess rule that denies dotted folders, or a redirect of all traffic to another domain can break both the first certificate and later renewals.
7. Renewal and wildcard certificates
DirectAdmin renews Let's Encrypt certificates automatically, well before they expire, using the same kind of check as the first time. Renewal fails for the same reasons: if you move DNS to a proxy or another host, the next renewal breaks. The Expires column in the certificate list shows the current expiry date, so you can confirm a renewal happened.
A wildcard certificate (*.yourdomain.com) is not something you request either. Prefer wildcard certificates is ticked by default on the ACME settings tab: if a single wildcard certificate can be issued to cover the domain and its subdomains, DirectAdmin issues one; if it cannot, DirectAdmin issues a certificate with the exact names instead. A wildcard needs DNS validation rather than the file check, which depends on where your DNS is hosted, so seeing exact names in the certificate list is normal and works just as well.
8. Where Domain India hosting fits
Every Domain India shared hosting plan includes free SSL: AutoSSL with Let's Encrypt on cPanel, and Let's Encrypt in DirectAdmin. DirectAdmin plans also include weekly backups with JetBackup. Compare plans and live prices on DirectAdmin hosting.
If you are on cPanel instead, see AutoSSL in cPanel.
Is the Let's Encrypt SSL certificate free on Domain India DirectAdmin hosting?
Yes. The certificate costs nothing, and you do not have to request it. DirectAdmin issues a Let's Encrypt certificate automatically once your domain points at your hosting, and renews it automatically.
How long does a Let's Encrypt certificate last?
Let's Encrypt certificates are short-lived, 90 days or less, and are meant to be renewed automatically. DirectAdmin renews them well before they expire, so you don't need to do anything while your domain keeps pointing to the server.
Where do I see my SSL certificate in DirectAdmin?
Open Account Manager › SSL/TLS Certificates. The Manage certificates tab lists each certificate with its DNS names, validity and expiry date, and lists any names that could not get a certificate along with the reason.
Why has DirectAdmin not issued a Let's Encrypt certificate for my domain?
Usually because the domain or www does not yet point to the DirectAdmin server, a proxy or CDN answers instead, or a CAA record allows only another certificate authority. Fix the DNS and wait; DirectAdmin retries on its own. If it still fails, open a support ticket with the domain name.
Do I need to include www in the certificate?
You do not choose the names. DirectAdmin tries the domain, www, mail, ftp, pop and smtp by default, and a name gets a certificate only if it reaches the server. For www to be covered, give it a DNS record that points to your hosting.
How do I force HTTPS once the certificate is in place?
Turn on DirectAdmin's HTTPS redirect option if your panel shows it, or add a RewriteRule to the .htaccess file in public_html that redirects http to https with a 301. Use one method only.
Can I get a wildcard certificate in DirectAdmin?
DirectAdmin decides this by itself. Prefer wildcard certificates is ticked by default, so a single wildcard certificate is issued when that is possible; when it is not, DirectAdmin issues a certificate with the exact names instead.
Ready to secure your site? Check that your domain points to your hosting with How do I change my nameservers, then open your hosting services to reach DirectAdmin, or compare DirectAdmin hosting plans.
Send us the domain and the reason DirectAdmin shows under Automatic certificate provisioning, and we will check the DNS and the certificate with you.
Open a support ticket