If your website is hosted with another company or on your own server, you still need an SSL certificate for https://. Domain India does not sell SSL certificates, for its own hosting or anywhere else. Almost all our hosting includes free SSL, and for any other host you get a certificate from that host, from Let's Encrypt, or from a certificate authority. This guide shows the right route for each case and how to install the certificate.
On Domain India hosting, SSL is free and there is nothing to order. On another host, first check its control panel: most hosts now issue a free Let's Encrypt certificate automatically. On your own server, use an ACME client such as Certbot to get and renew a free certificate. Buy a paid certificate from a certificate authority only when a bank, payment partner or tender asks for organisation validation. Whichever route you take, never share your private key.
1. Which situation are you in?
| Your website is on | What to do | Cost |
|---|---|---|
| Domain India hosting | Nothing to order: free SSL is included with almost all plans and issued in your control panel | Free with hosting |
| Another hosting company | Use that host's free SSL or AutoSSL option, or upload a certificate you bought | Usually free |
| Your own VPS or server | Get a Let's Encrypt certificate with an ACME client such as Certbot | Free |
| Any of these, with an organisation-validation requirement | Buy an OV or EV certificate from a certificate authority and install it | Paid, from the certificate authority |
Your domain can be registered with Domain India and hosted anywhere. The certificate belongs where the website runs, not where the domain is registered.
2. On Domain India hosting: free SSL is included
Almost all Domain India hosting includes free SSL, and there is no certificate to buy from us. On cPanel, AutoSSL issues and renews a Let's Encrypt certificate automatically once your domain points at your hosting. On DirectAdmin and Windows (Plesk) hosting, you request the free Let's Encrypt certificate once in the panel, and it then renews on its own.
For the steps and fixes, see ordering an SSL certificate and enabling free SSL with Let's Encrypt.
If you are thinking of moving your site to us, free SSL comes with our cPanel and DirectAdmin hosting, so the plan price is the price of a secure site. Compare plans on cPanel hosting.
3. On another hosting company: use its free SSL first
Most hosting companies now include free certificates. Look in the control panel for an option such as SSL/TLS Certificates, AutoSSL, Let's Encrypt or SSL Manager, and turn it on for your domain and its www version.
The certificate is only issued when the domain points at that host. If your domain is registered with Domain India, set its nameservers or DNS records to the ones your host gives you; see how to change your nameservers.
If the host offers no free option, get a certificate from a certificate authority (section 5) and upload it using the host's instructions.
4. On your own server: Let's Encrypt with Certbot
This section applies to a VPS or server you manage yourself. Let's Encrypt is a free, automated certificate authority trusted by every current browser. An ACME client proves you control the domain, installs the certificate and renews it before it expires.
On a Linux server with nginx or Apache, Certbot is the most common client. The Certbot website gives install instructions for your operating system and web server. Once installed:
# nginx
sudo certbot --nginx -d example.com -d www.example.com
# Apache
sudo certbot --apache -d example.com -d www.example.com
# Check that automatic renewal works
sudo certbot renew --dry-runBefore you run it, point the domain at the server and open ports 80 and 443 in the firewall. Alternatives include acme.sh, and web servers such as Caddy that obtain certificates on their own. On Windows servers with IIS, use an ACME client built for Windows, such as win-acme.
Let's Encrypt certificates last 90 days or less, and Let's Encrypt no longer emails expiry reminders. Make sure renewal runs automatically and test it with a dry run. Paid certificates are getting shorter too: the maximum lifetime for publicly trusted certificates is being reduced in stages from 2026, so plan for renewal every few months, not once a year.
5. Buying a paid certificate from a certificate authority
A paid certificate encrypts traffic no better than a free one. What you pay for is validation and, sometimes, a warranty:
| Type | What is checked | When you need it |
|---|---|---|
| DV (domain validated) | Control of the domain | Same as a free Let's Encrypt certificate; rarely worth paying for |
| OV (organisation validated) | Domain plus your registered organisation | When a bank, payment partner or tender asks for it |
| EV (extended validation) | Stricter checks on the organisation | Only if a contract specifically requires it; browsers no longer show a special address bar |
| Wildcard | Covers every first-level subdomain, such as *.example.com | Many subdomains; free wildcards are possible with DNS validation |
The steps are the same with any certificate authority:
- Generate a CSR and private key on the server that will use the certificate.A control panel does this for you; on your own server, use OpenSSL or your web server's tools. See how to generate a CSR.
- Order the certificate.Paste the CSR into the certificate authority's order form.
- Complete validation.Usually by email to an address at the domain, a DNS record, or a file on the website. For a DNS record, add it wherever the domain's DNS is managed, which is usually your host if you use its nameservers.
- Install the certificate and CA bundle.Paste or upload the certificate and the intermediate (CA bundle) files. The panel matches them to the stored private key.
- Test.Open the site over
https://, check the padlock, and confirm every hostname you need is covered.
6. Installing a certificate in common control panels
Menu names change between versions, so follow your host's own guide where it has one. In general:
- cPanel: open Security › SSL/TLS Certificates, then the Installation tab. Choose the domain, paste the certificate (and the CA bundle if asked) and click Install Certificate.
- Plesk: open the domain in Websites & Domains, go to SSL/TLS Certificates, upload or paste the certificate, private key and CA bundle, then make sure the domain's hosting settings use the new certificate.
- Other panels: look for SSL, TLS or HTTPS settings, and a "custom certificate" option.
After installing, redirect http:// to https:// so every visitor gets the secure version.
The CSR is safe to share; the private key is not. No certificate authority or hosting support team needs it by email or chat. If a key has been shared, generate a new CSR and key and have the certificate reissued.
7. Common problems
- "Certificate not trusted" on some devices. The CA bundle (intermediate certificates) is missing. Install the full chain.
- "Key does not match". The certificate was issued for a CSR made elsewhere. Install it where the CSR was generated, or reissue with a new CSR.
- Works for
example.combut notwww. The certificate doesn't includewww. Reissue with both names. - Padlock warning on some pages. Images or scripts load over
http://. Change them tohttps://. - Free certificate not issued. The domain doesn't point at the server yet, a CAA record blocks the certificate authority, or a proxy such as Cloudflare answers the check.
Frequently asked questions
Does Domain India sell SSL certificates for other hosting providers?
No. Domain India sells no SSL certificates. Almost all Domain India hosting includes free SSL. For a website hosted elsewhere, use that host's free SSL, get a free Let's Encrypt certificate on your own server, or buy a certificate from a certificate authority.
Is SSL free on Domain India hosting?
Yes. Almost all Domain India hosting includes free SSL. On cPanel, AutoSSL issues and renews a Let's Encrypt certificate automatically; DirectAdmin does the same, and on Windows (Plesk) you request it once in the control panel.
My domain is with Domain India but my website is hosted elsewhere. Where do I get SSL?
From the company or server that hosts the website. Point the domain at that host with its nameservers or DNS records, then turn on its free SSL or install your certificate there.
Is a free Let's Encrypt certificate as secure as a paid one?
Yes. The encryption is the same and every current browser trusts it. Paid OV and EV certificates add verified organisation details, which some banks, payment partners and tenders require.
How do I get a free SSL certificate on my own VPS?
Point the domain at the server, open ports 80 and 443, and use an ACME client such as Certbot to request a Let's Encrypt certificate. Certbot sets up automatic renewal; test it with certbot renew --dry-run.
Should I ever email my private key to anyone?
No. The private key stays on the server where it was generated. Only the CSR is shared with the certificate authority. If the key has been shared, generate a new one and reissue the certificate.
Ready to secure your site? If you host with us, check SSL in your control panel from My Hosting. If you are moving a site to Domain India, compare cPanel hosting, where free SSL is issued automatically. For anything else, open a ticket.
Tell us where your website is hosted and what you need the certificate for, and our team will point you to the right option.
Ask support