A padlock in the address bar protects only one connection: the visitor's browser talking to your site. An ASP.NET app sends data along several other routes too: to its database, to the mail server, to payment gateways and other APIs, and from your computer when you deploy. This guide goes through each connection on Domain India Windows hosting and shows how to keep the data on it encrypted.
Serve the site over HTTPS with the free Let's Encrypt certificate in Plesk and one HTTP-to-HTTPS redirect, then add HSTS and Secure cookies. Keep the database connection encrypted (TrustServerCertificate=True skips only the certificate check). Send mail on port 465 with SSL/TLS, call APIs only over https:// without disabling certificate checks, and deploy with FTP using explicit TLS. Never switch off TLS validation to make an error go away.
Installing the certificate and the redirect are covered in Configuring SSL for ASP.NET sites in Plesk and Installing SSL in Plesk. This article covers every other connection your app makes.
1. Map your app's connections
| Connection | Protect it with |
|---|---|
| Visitor's browser to your site | HTTPS, one redirect, HSTS, Secure cookies |
| Your app to its MSSQL database | An encrypted SQL connection |
| Your app to the mail server | SMTP on port 465 with SSL/TLS |
| Your app to payment gateways and APIs | HTTPS with certificate validation left on |
| You to Plesk | Plesk over HTTPS on port 8443 |
| Your computer to the server (deploys) | FTP with explicit TLS on port 21 |
2. Browser to site: HTTPS end to end
Install the free Let's Encrypt certificate in Plesk and force HTTPS in one place: the Plesk Permanent SEO-safe 301 redirect from HTTP to HTTPS option, a web.config rewrite rule, or UseHttpsRedirection() in ASP.NET Core. Then:
- HSTS:
app.UseHsts()in production, once every address you use has a certificate. - Cookies: mark authentication and session cookies Secure and HttpOnly.
- Forms and links: make every form post to an
https://or relative URL, so data is never submitted over HTTP.
For .NET Framework, the equivalent web.config rule is:
<system.webServer>
<rewrite>
<rules>
<rule name="Redirect to HTTPS" stopProcessing="true">
<match url="(.*)" />
<conditions>
<add input="{HTTPS}" pattern="^OFF$" />
</conditions>
<action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" />
</rule>
</rules>
</rewrite>
</system.webServer>Use it instead of the Plesk option, not as well.
3. App to database
Current SQL Server client libraries (Microsoft.Data.SqlClient 4.0 and later) encrypt the connection by default and check the server's certificate. If the check fails, you see "the certificate chain was issued by an authority that is not trusted". The fix used on hosting is:
Server=DB_HOST;Database=DB_NAME;User ID=DB_USER;Password=DB_PASSWORD;TrustServerCertificate=True;TrustServerCertificate=True keeps the connection encrypted and skips only the certificate check. Don't add Encrypt=False to silence errors. Your app reaches the database from the hosting server; the SQL Server port is closed to the outside world. Details: What to use for the MSSQL connection string.
4. App to mail server
Send through mail.yourdomain.com on port 465 with SSL/TLS from the first byte. Port 587 is closed on Windows hosting. .NET's System.Net.Mail.SmtpClient can't use port 465, so use MailKit with SecureSocketOptions.SslOnConnect. The code is in Configuring email for ASP.NET in Plesk.
5. App to payment gateways and APIs
- Use
https://URLs only for every API your app calls. - Leave certificate validation on. Never set
ServerCertificateCustomValidationCallbackto accept any certificate, orServicePointManager.ServerCertificateValidationCallbackto returntrue. That turns HTTPS into an unauthenticated connection anyone in between can read. - Let the operating system choose the TLS version. On .NET Framework, target 4.7 or later and don't hard-code
ServicePointManager.SecurityProtocol, so connections use TLS 1.2 or newer as the server supports. Modern .NET does this by default. - Reuse
HttpClientthroughIHttpClientFactoryin ASP.NET Core rather than creating one per request.
If an API call fails with a certificate error, check the URL and the provider's certificate, not the validation setting.
6. Payment and webhook callbacks
Payment gateways call back to your site to confirm payments. Register the callback URL with https://, verify each callback's signature as the gateway's documentation describes, and never trust an amount or status sent from the browser alone.
7. You to the server
- Plesk: open it with the Plesk button in the client area, or at
https://yourdomain.com:8443. Both use HTTPS. - FTP: in FileZilla or WinSCP choose Require explicit FTP over TLS on port 21. Plain FTP sends your password unencrypted. Windows hosting has no SSH or SFTP.
- Webmail and mail apps: include webmail and mail in your Let's Encrypt certificate so those connections don't show certificate warnings.
8. Where Domain India Windows hosting fits
Every Windows plan includes free SSL, Plesk over HTTPS and FTP with explicit TLS. The cards show live prices, excluding 18% GST.
- 30 GB Storage
- 150 GB Monthly Bandwidth
- 5 Websites
- 50 Email Accounts
- 100 GB Storage
- Unmetered Bandwidth
- 15 Websites
- 100 Email Accounts
For hardening beyond encryption, such as passwords, errors and updates, see How to secure your ASP.NET applications on Plesk.
Does an SSL certificate protect everything my ASP.NET app sends?
No. It protects the connection between visitors' browsers and your site. Your app's connections to its database, the mail server and external APIs each need their own encryption settings.
Is TrustServerCertificate=True safe for my database connection?
It keeps the connection encrypted and skips only the check of the server's certificate. For a database on the same hosting platform it is the standard setting. Never use Encrypt=False to hide errors.
Which port should my app use to send email securely?
Port 465 with SSL/TLS from the start of the connection, on mail.yourdomain.com. Port 587 is closed on Domain India Windows hosting.
How do I fix a certificate error when my app calls an API?
Check the URL and the provider's certificate, and make sure .NET Framework apps target 4.7 or later without a hard-coded TLS version. Never disable certificate validation in code.
How do I upload files securely to Windows hosting?
Use FTP on port 21 with Require explicit FTP over TLS in FileZilla or WinSCP, or the Plesk File Manager over HTTPS. SFTP is not available because Windows hosting has no SSH.
Ready to secure your ASP.NET app end to end? Compare the Windows hosting plans, or open a ticket if a TLS error won't go away. Support is on 24/7 live chat, and tickets get a first response within 15 minutes.
Free SSL, Plesk over HTTPS and FTP with explicit TLS on every Windows plan.
See Windows hosting plans