SSL certificates

The padlock, installed and never expired.

We issue the certificate, install it, move every visitor onto HTTPS and renew it long before the date - on any site and any server.

Get a quote

What "installed properly" means

A certificate on the server is the start. These are the parts that make visitors, browsers and search engines trust the site.

  • Every address coveredThe domain with and without www, and every subdomain with a wildcard certificate.
  • HTTPS forcedOld http links redirect to the secure address, once, without a loop.
  • No mixed contentImages and scripts loading over http are found and fixed, so the padlock does not break on some pages.
  • Modern encryptionOld protocols switched off and a strict HTTPS policy sent, so browsers never fall back.
  • Renewed on timeRenewal runs by itself weeks ahead, and a daily check tells us if it ever fails.
  • Any serverSites we host get it as standard; we install it on yours, wherever it runs.

Which kind of certificate fits

Certificates differ in how much is checked before they are signed and in which names they cover. The encryption is the same in all of them; what changes is the proof behind the padlock.

Certificate types compared: what is checked, how long issuing usually takes, and what each is for
What you want to know DVDomain validated OVOrganisation validated EVExtended validation WildcardEvery subdomain at one level Multi-domainSeveral names in one certificate
What is checked Control of the domain name Domain control, plus the legal organisation and its address Domain control, plus the strictest documented vetting of the legal entity Control of the domain, proven with a DNS record Control of every name on the list, each checked on its own
Names covered The names listed on it The names listed on it The names listed on it Any subdomain at one level, such as shop or blog; the bare domain is listed beside it Several different names and domains in one certificate
Typical time to issue Minutes, fully automated Hours to days, people review documents Days, the longest manual review As quick as its validation level, once the DNS record is in place Set by its strictest name to validate
Same encryption strength Yes Yes Yes Yes Yes
Organisation named in the certificate No Yes Yes Depends on its validation level Depends on its validation level
Best for Websites, shops, blogs and APIs; the everyday choice Companies that want their verified name inside the certificate Regulated or high-trust organisations; browsers no longer give it a special address-bar display Sites with many subdomains, or ones added often A few related sites under one certificate

Wildcard and multi-domain say which names a certificate covers. DV, OV and EV say how much was checked about who asked for it. The two choices are made separately. Not sure which one fits? Send us the address.

General facts, from the CA/Browser Forum Baseline Requirements and the Let's Encrypt documentation. Which type your site needs, we confirm when we quote it.

The life of a certificate, start to end

A certificate is not installed once and forgotten. It has a beginning, a working life and an end, and every stage has someone watching it. This is the order things happen in.

  1. Day one

    Issue

    The certificate authority checks that the domain is really yours, with a file on the site or a DNS record for a wildcard, and then signs the certificate. We handle the request.

  2. Day one

    Install

    We place it on the server, cover the domain with and without www, send old http links to the secure address and fix anything still loading over http.

  3. Weeks before expiry

    Renew

    Renewal runs by itself, 30 days before the certificate expires, so one slow day never turns into an expired padlock.

  4. Every day

    Expiry alert

    A daily check reads the expiry date. If a renewal ever fails, we hear about it weeks before any visitor would see a warning.

  5. Only if needed

    Revoke

    If the private key is exposed or the certificate was issued for the wrong details, the authority marks it untrusted before its date. A new certificate is then issued and installed the same way as the first.

Why renewal has to be automatic

The CA/Browser Forum limits how long a public certificate may last: 200 days since March 2026, 100 days from March 2027 and 47 days from March 2029. The shorter the life, the more often this cycle repeats, and a date kept by hand is a date waiting to be missed.

See how the server around the certificate is protected

Send us the address

Tell us the domain and where the site runs. We will tell you what it needs and quote it the same day.

Get a quote

Questions and answers

Do the sites you host get SSL included?

Yes. Sites we host get a certificate as standard, renewed automatically. We also install and renew certificates on sites that run elsewhere.

When are certificates renewed?

Renewal runs by itself 30 days before a certificate expires, and a daily check of the expiry date tells us if a renewal ever fails.

Can one certificate cover all my subdomains?

Yes. A wildcard certificate covers every subdomain. The certificate authority checks a DNS record on the domain before it signs one.

What is the difference between DV, OV and EV?

How much the authority checks about who asked for the certificate. The encryption is the same in all of them; what changes is the proof behind the padlock.

MickeyAnswers in seconds