Manage SSL certificates and Force HTTPS
Install or renew the free certificate for a website and its mail services, or for mail only, then safely force visitors onto HTTPS.
Where Websites โ your website โ Advanced โ Security
What this is for
- Install a free certificate for the website and mail, or for mail only.
- See whether the certificate is active and when it expires.
- Redirect website visitors from HTTP to secure HTTPS.
Before you start
- Confirm the domain's DNS points to the correct Enhance website or mail server.
- Decide whether you need website-and-mail coverage or mail-only coverage.
Take care
Do not force HTTPS until the certificate is valid. Otherwise visitors may be redirected into a certificate error.
Steps
-
1
Open Websites, select the correct website, press Advanced across the top and choose Security from the menu.
-
2
Find the row for the exact domain. If several domains are listed, check the spelling carefully before continuing.
-
3
Press the three dots at the far right of that domain's row to open its certificate actions.
-
4
Choose Request Let's Encrypt certificate when the domain points to this website. This is the normal website choice and includes the domain's hosted mail certificate coverage.
-
5
Choose Request Let's Encrypt certificate for mail. only when the website is hosted somewhere else but email for the domain is hosted in Enhance.
-
6
Wait while Enhance requests and installs the Let's Encrypt certificate. Leave the page open until the row reports Active or shows a clear error.
-
7
Check that Certificate says Let's Encrypt and review the Expiry date. Enhance normally renews this certificate automatically.
-
8
Open https:// followed by the domain in a new browser tab. Continue only when the page loads without a certificate warning.
-
9
Turn on Force HTTPS for a hosted website after the HTTPS test succeeds. This sends anyone using http:// to the secure address.
-
10
Test the homepage, WordPress login, forms and any checkout or API callbacks. If installation fails, check that the domain's DNS points to the correct Enhance server before retrying.
Check it worked
- The row shows Active, Let's Encrypt and a future expiry date.
- The HTTPS website opens without a browser warning and, if Force HTTPS is on, http:// redirects to https://.
What the controls do
| Control | What it means |
|---|---|
| Status | Whether the certificate is installed and active. |
| Let's Encrypt | An automatically issued and normally renewed certificate. |
| Three-dot menu | The vertical dots at the far right of the domain row. Press them to reveal the exact certificate actions shown in the screenshot. |
| Request Let's Encrypt certificate | The normal website choice. Use it when the website is hosted here; it requests the website certificate and its hosted mail coverage. |
| Request Let's Encrypt certificate for mail. | The mail-only choice. Use it when Enhance hosts email but the website itself is hosted elsewhere. |
| Force HTTPS | Redirects website requests from insecure http:// to secure https:// after the certificate works. |