SSL & Security

Installing SSL in Plesk

By the Domain India teamPublished 8 min read
Knowledge base article
Contents (10 sections)

SSL puts the padlock on your website and encrypts everything between your visitors and the server. Domain India Windows hosting plans include free SSL from Let's Encrypt, managed in the Plesk control panel. This is our complete guide to SSL in Plesk: installing the free certificate, covering webmail and mail, redirecting to HTTPS, renewals, uploading a certificate from another provider, and fixing errors.

Key takeaways

In Plesk, open SSL/TLS Certificates for your domain and install the free Let's Encrypt certificate, ticking the options for www, webmail and mail. Plesk renews it automatically. Then make sure the 301 redirect from HTTP to HTTPS is on in the domain's hosting settings. The domain must already point at your hosting for Let's Encrypt to issue the certificate.

1. What SSL you get on Windows hosting

Every Domain India Windows hosting plan lists free SSL, and ASP Enterprise also lists wildcard SSL. The certificate comes from Let's Encrypt, a free certificate authority trusted by every current browser.

We checked Windows-hosted sites on 23 September 2026: nearly all served a valid Let's Encrypt certificate and already redirected HTTP to HTTPS. A few did not, and on most accounts the webmail address still used Plesk's default certificate. So check your own domain rather than assuming it is covered. Sections 2 and 3 show how.

2. Before you install

Let's Encrypt checks that you control the domain by fetching a file from your website over port 80. That only works if:

  • the domain points at your Windows hosting. It must use the hosting nameservers, or have A records for the domain and www pointing at your server IP. See how to change your nameservers;
  • DNS has updated. After a nameserver change, allow time for it to spread before you install;
  • nothing in front blocks the check. If you use Cloudflare's proxy, pause it while you install, or use Cloudflare's own SSL mode settings.

3. Install the free Let's Encrypt certificate

  1. Open Plesk.
    In the client area, go to Hosting › My hosting and click the Plesk button on your domain's row.
  2. Open SSL/TLS Certificates.
    Under Websites & Domains, find your domain and click SSL/TLS Certificates.
  3. Choose Let's Encrypt.
    Click Install (or Get it free) in the Let's Encrypt section.
  4. Pick what to secure.
    Enter your email address for expiry notices. Tick the domain, the www version, webmail and mail if they are offered. Leave the wildcard option off unless you need it (see section 6).
  5. Install.
    Click Get it free or Install and wait a minute while Plesk completes the check.
  6. Test.
    Open https://yourdomain.com and https://webmail.yourdomain.com in a private window and click the padlock.

Menu labels can change slightly between Plesk updates. If you can't find an option, open a ticket and we will point you to it.

Tick webmail and mail as well

If you leave them out, webmail at https://webmail.yourdomain.com keeps Plesk's default certificate and shows a browser warning, and mail apps may warn about mail.yourdomain.com. Reissuing the certificate with those options ticked fixes it.

4. Turn on the HTTP to HTTPS redirect

A certificate alone doesn't stop people reaching the insecure http:// version. The redirect does:

  1. In Plesk, open your domain's Hosting Settings (under Hosting & DNS on newer Plesk versions).
  2. Make sure SSL/TLS support is on and your Let's Encrypt certificate is selected.
  3. Tick Permanent SEO-safe 301 redirect from HTTP to HTTPS and click OK.

Many Windows accounts already have this on. To check, open http://yourdomain.com; it should change to https:// on its own. The detailed guide, including a web.config alternative, is HTTPS redirect in Plesk.

Windows hosting runs IIS, not Apache, so .htaccess redirect rules have no effect here.

5. Renewal: what Plesk does for you

Let's Encrypt certificates are short-lived by design, and Plesk renews them automatically before they expire. You don't need to do anything, as long as the domain still points at your hosting. Renewal fails if:

  • the domain has moved to another server or its DNS changed;
  • a proxy or firewall rule blocks the check on port 80;
  • a rewrite rule in your site sends the check request somewhere else.

If renewal fails, Plesk emails the address you entered. You can reissue the certificate from the same SSL/TLS Certificates page once the cause is fixed. The steps are in managing SSL certificates in Plesk.

6. Wildcard certificates

A wildcard certificate covers every subdomain, such as shop.yourdomain.com and blog.yourdomain.com. ASP Enterprise lists wildcard SSL. Let's Encrypt only issues wildcards after a DNS check, which Plesk can complete automatically when your domain's DNS is managed by the hosting. If your DNS is elsewhere, the check and every renewal need a manual TXT record, so it is usually simpler to secure each subdomain with its own free certificate. Ask support if you're unsure.

7. Using a certificate from another provider

Some businesses need an organisation-validated (OV or EV) certificate bought from a certificate authority. Plesk accepts those too:

  1. Create the request.
    On SSL/TLS Certificates, add a certificate and fill in your details. Plesk generates the CSR and keeps the private key. Send the CSR to your certificate provider.
  2. Upload the certificate.
    When the provider issues it, open the same entry and paste or upload the certificate and the CA bundle (intermediate certificates) they gave you.
  3. Assign it.
    In Hosting Settings, select the new certificate and save.
  4. Test.
    Check the padlock and an online SSL checker to confirm the full chain is served.

An uploaded certificate does not renew itself. Renew it with your provider before it expires and upload the new one. Always include the CA bundle: without it, some phones and older browsers show a warning even though the certificate is valid.

8. Troubleshooting

ProblemMost likely cause and fix
Let's Encrypt install failsDomain or www not pointing at your hosting yet; fix DNS and retry
Browser still warns after installCertificate not selected in Hosting Settings, or www not included
Webmail shows a warningWebmail not included; reissue with the webmail option ticked
Mixed content, padlock missingPage loads images or scripts over http; update them to https
Too many redirectsRedirect set twice, or a proxy set to flexible SSL; keep one redirect
Uploaded certificate rejectedPrivate key doesn't match the CSR; create a new CSR and reissue

For a WordPress site, also change both site addresses under Settings › General to https://.

9. Where Domain India Windows hosting fits

Windows hosting is for ASP.NET and MSSQL websites, managed in Plesk, with free Let's Encrypt SSL on every plan. On cPanel, DirectAdmin and Webuzo hosting, SSL works differently; see how to enable free SSL with Let's Encrypt.

ASP Starter
₹164.87/mo + GST
  • 10 GB Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details
ASP Business
₹328.83/mo + GST
  • 30 GB Storage
  • 150 GB Monthly Bandwidth
  • 5 Websites
  • 50 Email Accounts
See plan details
ASP Enterprise
₹493.70/mo + GST
  • 100 GB Storage
  • Unmetered Bandwidth
  • 15 Websites
  • 100 Email Accounts
See plan details

For a wider tour of Plesk, read the Windows hosting guide.

Frequently asked questions

Is SSL free on Domain India Windows hosting?

Yes. Every Windows hosting plan lists free SSL, using Let's Encrypt certificates that you install and manage in Plesk. Plesk renews them automatically.

How do I install Let's Encrypt in Plesk?

In Plesk, open SSL/TLS Certificates for your domain, click Install in the Let's Encrypt section, tick the domain, www, webmail and mail, and click Get it free. The domain must already point at your hosting.

Why does Let's Encrypt fail to install?

Usually because the domain or its www version does not point at your Windows hosting yet, or a proxy such as Cloudflare blocks the check. Fix DNS, wait for it to update, and try again.

Do I need to renew my Let's Encrypt certificate?

No. Plesk renews Let's Encrypt certificates automatically before they expire, as long as the domain still points at your hosting. Certificates uploaded from another provider must be renewed by you.

Why does webmail show a certificate warning?

The webmail address is not included in your certificate, so it uses Plesk's default one. Reissue the Let's Encrypt certificate with the webmail option ticked.

How do I force HTTPS in Plesk?

In the domain's Hosting Settings, keep SSL/TLS support on with your certificate selected, tick Permanent SEO-safe 301 redirect from HTTP to HTTPS, and click OK. Windows hosting uses IIS, so .htaccess rules have no effect.

Can I install an SSL certificate I bought elsewhere?

Yes. Generate a CSR in Plesk, send it to your provider, then upload the issued certificate and CA bundle on the SSL/TLS Certificates page and select it in Hosting Settings. You renew it yourself.

Ready to secure your site? Compare Windows hosting plans, read HTTPS redirect in Plesk, or open a ticket if the certificate won't install.

SSL not installing?

Tell us the domain and the error Plesk shows, and our team will check DNS and the certificate for you.

Open a support ticket

Ready when you are

Get Windows hosting from ₹164.87/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Install Free SSL in Plesk (Let's Encrypt) | Guide