> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.xynta.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Generate a free SSL certificate

**Your xYnta hosting plan comes with AutoSSL by default — your website automatically receives a free SSL certificate. In most cases you don't have to do anything. Can't get the certificate generated automatically? Then you can request one manually through DirectAdmin.**

|| This article applies to our [Web Hosting](https://www.xynta.com/en/webhosting), [Email Hosting](https://www.xynta.com/en/email-hosting) and [Reseller Hosting](https://www.xynta.com/en/reseller-hosting) plans (control panel DirectAdmin). Using [WordPress Hosting](https://www.xynta.com/en/wordpress-hosting) (Plesk)? Follow the article [Generate a free SSL certificate – WordPress Hosting](https://help.xynta.com/en/article/generate-a-free-ssl-certificate-wordpress-hosting-1cipkt1/) instead.

* [Automatic SSL (AutoSSL)](#3-automatic-ssl-autossl)
* [Checking your SSL status](#3-checking-your-ssl-status)
* [Generate SSL manually — method 1 (recommended)](#3-generate-ssl-manually-method-1-recommended)
* [Generate SSL manually — method 2](#3-generate-ssl-manually-method-2)
* [Points of attention](#3-points-of-attention)
* [Instructional video](#3-instructional-video)

### Automatic SSL (AutoSSL)

All our hosting plans come with **AutoSSL**. As soon as you add a domain to your plan, a free SSL certificate is automatically requested and installed — usually within a few hours.

In most cases you don't need to do **anything** yourself. Renewal of the certificate also happens fully automatically.

||| For a successful request, your domain name must correctly point to your xYnta plan. If that's not yet the case — for example during a migration — the certificate cannot be generated until DNS is in order.

### Checking your SSL status

Want to quickly see whether your website has a valid SSL certificate and when it expires? Use the [website check](https://www.xynta.com/en/support/website-check):

1. Go to [xynta.com/en/support/website-check](https://www.xynta.com/en/support/website-check).
2. Enter your domain name and start the **Quick scan**.
3. Under **Security** you'll see the status of your SSL certificate, including its validity period and any points of attention.

### Generate SSL manually — method 1 (recommended)

Is AutoSSL not active or do you want to request a certificate yourself? This is the recommended route — it covers your main domain, subdomains and domain pointers in one go.

1. Log in to DirectAdmin — via [Single Sign-On](https://help.xynta.com/en/article/logging-in-to-hosting-package-via-single-sign-on-sso-1biycbb/) or directly at `https://yourdomain.com:2222`.
2. Under **Account Manager**, click **SSL Certificates**.
3. Click the **Use the best matching certificate** tab.
4. Click the green **SAVE** button.
5. In the second submenu, click the **Manual Trigger** tab.
6. Tick all three options:

* **Wildcard:** `*.``yourdomain.com`, `yourdomain.com`
* **Sub-Domains**
* **Domain Pointers**

7. Click **RETRIGGER FOR THIS DOMAIN**.

An SSL certificate is now generated for all domain names and subdomains on your hosting plan. This process takes about 30 minutes.

You can track the status via:

* **Upcoming new attempts** — for pending requests.
* **Certificate** — for installed SSL certificates.

### Generate SSL manually — method 2

Use this method if you want more control over which specific domain names receive a certificate — for example if you only want to request an SSL certificate for one specific subdomain.

1. Log in to DirectAdmin — via [Single Sign-On](https://help.xynta.com/en/article/logging-in-to-hosting-package-via-single-sign-on-sso-1biycbb/) or directly at `https://yourdomain.com:2222`.
2. Under **Account Manager**, click **SSL Certificates**.
3. Click the **Get automatic certificate from ACME Provider** tab.
4. Tick the domain names and subdomains for which you want to generate an SSL certificate.
5. Click **SAVE** at the bottom of the page.

Depending on the number of domains, it takes about 30 minutes before the Let's Encrypt certificates are generated.

### Points of attention

* **DNS must be correct** — only correctly linked domains and subdomains can receive a free SSL certificate. Check your DNS settings with the [website check](https://www.xynta.com/en/support/website-check) before requesting a certificate. For an externally registered domain, it must point to the server IP before the certificate can be generated.
* **Email SSL errors** — if email works on one device but not another, first regenerate the hosting SSL certificate and allow approximately 15 minutes for generation. Phones and Mac Mail may cache an old certificate. Remove the email account from the device, restart it, and add it again using the email setup instructions. Use the hostname that appears on the new certificate (normally `mail.yourdomain.com`). If that still fails, temporarily try the main domain without the `mail.` prefix.
* **Allow time for generation** — after enabling SSL, allow approximately 30–60 minutes for the certificate to be generated and for services to start working.
* **Don't keep retrying on errors** — if generating fails, do **not** keep trying repeatedly. Resolve the error shown first to avoid temporary blocks at Let's Encrypt (rate limits).
* **Only active domains** — a domain name must be actively linked to your hosting plan before an SSL certificate can be generated.

### Instructional video

Prefer to see how it works? Watch our short instructional video on generating an SSL certificate:

${youtube}[Generate a free SSL certificate](ILjkwy2w9DE)

Can't figure it out? [Feel free to get in touch](https://www.xynta.com/en/support/contact) — we're happy to help.