Request a Let’s Encrypt certificate
Choose the hostnames to secure in the Wizard and resolve domain-validation issues.
Where Tools → Security → SSL/TLS Certificates → Wizard
Before you start
- Add the domains to cPanel and point public DNS at the intended hosting service. The certificate authority must verify control of each selected name.
- Include the real hostnames users need. A certificate for example.com does not automatically cover mail.example.com or every subdomain.
Steps
-
1
Open SSL/TLS Certificates and choose Wizard. Expand Add the domains that you want to secure with this certificate.
-
2
Review Selected Domains, then click Continue. cPanel checks domain control; selecting a name does not guarantee it will validate.
-
3
Read Resolve Issues and correct any DNS or validation problems. Do not request repeatedly without addressing the reported cause. A wildcard has additional validation requirements.
-
4
Wait for successful issuance/installation, then check Status. Keep the required DNS and validation paths working so future managed renewal can succeed.
-
5
Tick the required names. For a website, normally include its main and www names if both are used. Include mail or other service hostnames only when those names belong on this certificate. Search the list if a name is not visible.
Select actual hostnames, including mail only if it belongs on this certificate. -
6
Under Select the product that you would like for this certificate, choose Let’s Encrypt Certificate when you are ready to request it. The screenshot shows this option before submission.
Continue reveals the Let’s Encrypt Certificate button and Resolve Issues section.
Check it worked
- Confirm each intended hostname has a trusted, unexpired certificate in Status.
- Test HTTPS and any covered mail service. If the hostname is missing from the certificate, fix coverage rather than bypassing the warning.