Websites & Email · SSL certificates

Work out which certificate your website needs, and what it costs

Everything your customers, your staff and your inbox touch over the public internet. Two questions decide which certificate you need — what it has to cover, and how much you have to prove about who you are — and this page answers both with prices rather than an enquiry form.

  • “Not secure” is a bounce, not a warningChrome and Safari label an unencrypted page in the address bar before a visitor has read a word of it. On a checkout or a contact form that is the end of the session, and you never see it in your analytics as a certificate problem.
  • An expired certificate is a full-screen stopNot a subtle badge — an interstitial the visitor has to click through, and one most will not. Every certificate here can be bought for two years and reissued free in between.
  • Encryption is identical at every priceDV, OV and EV all give the same key strength and the same padlock. You are paying for what the authority checked before signing, so buy the level your customers or your auditor need and not a penny more.
  • One certificate usually covers more than you thinkA wildcard covers every subdomain you will ever add; a multi-domain certificate covers up to 250 unrelated names. Most people about to buy four certificates need one.
  • $14.99a year for one website
  • 69% offits list price of $49
  • $41.96to put your company name in it
  • Minutesfrom order to installed, on DV

1. What has the certificate got to cover?

This is about scope — how many names go inside the file. Get it wrong and you either pay for coverage you never use, or find out at install time that a hostname is missing and the reissue costs you an afternoon. Every website estate is one of these four shapes.

One website

acme.com + www.acme.com

A single domain, and conventionally the www version alongside it. Right for a brochure site, a blog, a landing page — anything running on one name and taking no logins or payments.

Cheapest certificate that fits Comodo PositiveSSL Certificate
  • Domain validated · issued in minutes
  • $10,000 warranty
from $14.99 $49 per year, before term discounts
Details

A site and every subdomain

shop. · blog. · app. · staging. — all under acme.com

One certificate covering every subdomain of the domain, including the ones you have not thought of yet, with no reissue when you add them. It works out cheaper than singles from about the third subdomain onward.

Cheapest certificate that fits Certum Commercial Wildcard SSL Certificate
  • Domain validated · issued in minutes
  • Covers unlimited subdomains of the domain
  • €400,000 warranty
from $79 $158 per year, before term discounts
Details

Several separate domains

acme.com + acme.co.uk + secondbrand.com

A wildcard only stretches across one registered domain. When the sites sit on two or three different ones, each name is listed explicitly instead — and you get one renewal date to diary rather than a spreadsheet of them.

Cheapest certificate that fits Comodo PositiveSSL Multi-Domain Certificate
  • Domain validated · issued in minutes
  • 3 hostnames included, up to 247 in total
  • $10,000 warranty
from $114 $165 per year, before term discounts
Details

Several domains and their subdomains

*.acme.com + *.acme.co.uk + *.secondbrand.com

The widest coverage a single certificate can carry. It is the expensive shape, so it earns its price when the alternative is genuinely four or five certificates — an agency estate or a group of brands.

Cheapest certificate that fits PositiveSSL Multi-Domain Wildcard SSL Certificate
  • Domain validated · issued in minutes
  • Covers unlimited subdomains of the domain
  • 3 hostnames included, up to 247 in total
  • $10,000 warranty
from $267.24 $356.32 per year, before term discounts
Details

2. How much do you have to prove?

All three levels give the padlock and identical encryption strength. What changes is how much the certificate authority verifies before it signs, how long that takes, and what a visitor or an auditor can find out about you from the certificate itself. Pick the level your customers need, then pick the shape above.

1

Domain validated (DV)

The authority checks one thing: that you control the domain. It does that with an email to an address at the domain or a DNS record, and signs within minutes. Nothing about your organisation is checked, and nothing about it appears in the certificate.

Right for: blogs, portfolios, marketing sites, staging — anything that takes neither payments nor logins.

Recommended COMODO

Comodo PositiveSSL Certificate

The cheapest certificate on this site that a browser will trust without complaint, and the one most sites should be buying. Ordered and installed inside an hour.

  • Domain validated · issued in minutes
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $14.99 $49 per year, before term discounts
Details
Alternative RAPIDSSL

RapidSSL Certificate

A different root and a name your host’s documentation has probably heard of. Identical encryption and the same minutes-to-issue; buy it if something in your stack specifies the brand.

  • Domain validated · issued in minutes
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $16.95 $69 per year, before term discounts
Details
2

Organisation validated (OV)

The authority checks that your registered company exists, that it is reachable at a published number, and that it controls the domain, then writes the company name into the certificate. One to three working days, and you will get a phone call.

Right for: company sites, customer portals, staff logins, B2B — anywhere a security questionnaire is going to land.

Recommended CERTUM

Certum Trusted SSL Certificate (OV)

The cheapest way to get a vetted company name inside a certificate. For most businesses that name is the whole reason to move off DV, and there is no need to pay half as much again for it.

  • Organisation validated · issued in 1-3 days
  • $10,000 warranty
from $41.96 $158 per year, before term discounts
Details
Larger warranty GEOTRUST

GeoTrust True BusinessID SSL Certificate

The same organisation vetting with a far larger warranty behind it, and the GeoTrust name. Buy it when a contract or an insurer specifies a warranty figure rather than a validation level.

  • Organisation validated · issued in 1-3 days
  • $1,250,000 warranty
  • Free unlimited reissues for the whole term
from $86 $199 per year, before term discounts
Details
3

Extended validation (EV)

Legal, physical and operational existence of the business, checked against public records under the strictest rules the industry defines. Three to seven working days, and longer if your registry entry is out of date.

Right for: checkouts, payments, fintech, banking, healthcare — anywhere money or medical data changes hands.

Recommended CERTUM

Certum Premium EV SSL Certificate

Full EV vetting at roughly two-thirds off what the mainstream brands charge for it. If you need EV because a policy says EV, this satisfies the policy.

  • Extended validation · issued in 7 days
  • €1,000,000 warranty
from $129 $299 per year, before term discounts
Details
Largest warranty GEOTRUST

True BusinessID with Green Bar EV

The same EV vetting, faster, from a brand procurement teams recognise, and with the biggest warranty on this page behind it.

  • Extended validation · issued in 1-5 days
  • $1,500,000 warranty
  • Free unlimited reissues for the whole term
from $188 $199 per year, before term discounts
Details

3. Email

Email splits into two different problems that get asked about as one question, and they need different certificates. One is issued to a person and travels with the message; the other is issued to hostnames and lives on the server.

1

Signing and encrypting the messages

An S/MIME certificate is issued to a person, not to a domain. It signs outgoing mail so a recipient can prove it genuinely came from you, encrypts the body so only they can read it, and doubles as a client certificate for logging in to portals and VPNs without a password. One per mailbox.

Typically: finance teams, legal, anyone whose signature on an email has to mean something.

Recommended CPAC

CPAC Basic - Personal Authentication Signature

Proves control of the address and signs and encrypts from any normal mail client. The right starting point unless your name specifically has to appear in the certificate.

  • Email Validation
  • Installs in Outlook, Apple Mail, Thunderbird and mobile
  • Also works as a client certificate for portal and VPN logins
  • Issued to one mailbox — buy one per person
from $16 $39 per year, before term discounts
Details
Name verified CERTUM

Certum Professional ID (S/MIME)

Your verified full name goes inside the certificate as well as the address, which is what a counterparty checks when a signature has to carry legal weight.

  • Identity Validation · issued in 1-3 days
  • $4,000 warranty
  • Your identity checked against documents before issue
  • Recognised for signing PDFs as well as email
from $29.95 $99 per year, before term discounts
Details
2

Securing the mail server itself

Your mail server answers on more names than anyone expects — mail., smtp., imap., webmail. and, on Exchange, autodiscover. Miss one and Outlook prompts every user every morning until somebody works out why. That is a multi-domain job.

Typically: Exchange, Microsoft 365 hybrid, Zimbra, MDaemon, Postfix and cPanel mail.

Covers every hostname COMODO

Comodo PositiveSSL Multi-Domain Certificate

Three hostnames included and room for far more, which is normally enough for mail, autodiscover and webmail on one file. Add the rest at checkout.

  • Domain validated · issued in minutes
  • 3 hostnames included, up to 247 in total
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $114 $165 per year, before term discounts
Details

Running Exchange, Zimbra or a hybrid tenant and want the hostname list worked out for you? That is covered in detail on the mail servers and webmail page.

What the wrong certificate — or no certificate — actually costs

Not an abstraction. These are the four things that go wrong on websites, in the order people usually notice them.

  • Visitors leave before the page finishes loading “Not secure” sits in the address bar of every unencrypted page, and an expired certificate gets a full-screen interstitial. Neither shows up in analytics as a certificate problem — it shows up as a bounce rate you cannot explain.
  • The name on the certificate does not match the name in the browser Buying for acme.com and serving www.acme.com, or covering the domain but not the subdomain the app runs on, produces exactly the same warning as having no certificate at all. This is the single most common mistake, and the four shapes above exist to prevent it.
  • Search and payment providers treat it as a signal HTTPS has been a ranking factor for years, card processors expect it on anything touching a payment flow, and browsers withhold modern APIs from insecure origins. None of that is negotiable per-site.
  • Renewal comes round and nobody owns it Certificates lapse on a Saturday, at whatever hour they were issued. Consolidating an estate onto one wildcard or one multi-domain certificate replaces five diary entries with one, which is usually the real argument for buying the wider shape.

Three things worth knowing before you order

EV no longer turns the address bar green

Extended validation certificates used to paint the address bar green with your company name in it. Every major browser removed that treatment years ago, so to a casual visitor an EV certificate now looks identical to a $15 one. It still means something — the vetting is real, the warranty is much larger, and the organisation details are inspectable in the certificate — but if you are buying EV for a visible green bar, you will not get one. Buy it because a policy, an auditor or a contract asks for it.

A wildcard covers one level, not all of them

A certificate for *.acme.com covers shop.acme.com and blog.acme.com, and it does not cover eu.shop.acme.com — the star matches a single label. Most estates never hit this; the ones that do are usually running regional or per-customer subdomains. If yours is one of them, a multi-domain wildcard or a second wildcard for the deeper level is the fix, and it is much cheaper to establish that now than after issue.

Sometimes a free certificate is the right answer, and we will say so

If your site is on a host that issues and renews Let's Encrypt certificates for you, your server can reach the internet on port 80, and nobody needs your company name inside the certificate, a free one is genuinely fine and you should use it. People buy here when the site is not internet-facing, when they want a one or two year cycle instead of renewing every ninety days, when one certificate has to cover a whole estate, or when they need organisation or extended validation — which no free authority issues. Ask us first if you are unsure; we would rather lose the sale than sell you something you did not need.

What comes with the price

  • Lowest price guaranteeFind the same certificate cheaper anywhere and we match it.
  • 10-day money backOn SSL certificates: cancel inside 10 days for a full refund. Email signing certificates are not covered. Read the policy.
  • Free unlimited reissuesChange a hostname or move host mid-term at no cost.
  • Free installation supportStuck on cPanel, IIS or a load balancer? Our engineers finish it with you.
  • Issued by the authority itselfSectigo, Comodo, GeoTrust, Thawte, RapidSSL or Certum sign it — not us. Same certificate, lower price.
  • Free tools, no sign-upCSR generator, checker, decoder and four more.

How the install actually goes

Three steps, and the same three whether the site is on cPanel, IIS, Nginx or a load balancer.

  1. Generate the request on the server Most control panels will create the signing request themselves and keep the private key on the box, which is safer than moving a key around. Where one cannot, our free CSR generator makes the request and gives you the matching key. Check it with the CSR decoder before you submit it — a typo in the domain costs a reissue.
  2. Order and validate Paste the request in at checkout. Domain validation is an email to an address at the domain or a DNS record and takes minutes; organisation validation adds a company check of one to three working days, extended validation three to five.
  3. Install the certificate and its chain This is where installs go wrong. Desktop browsers often forgive a missing intermediate; mobile browsers, mail clients and API integrations do not, so the site looks fine to you and broken to a quarter of your visitors. Confirm it from outside with the SSL checker, and if a certificate and key will not pair, the key matcher says why in seconds. Then redirect http to https so nobody lands on the unencrypted version.

Questions we get asked before people order

Does a more expensive certificate encrypt better?

No. A $15 DV certificate and a $2,000 EV certificate negotiate exactly the same ciphers and the same key strength. Everything you pay above the cheapest is buying vetting, warranty and brand — not security on the wire. Anyone who tells you otherwise is selling.

Do I need to cover both acme.com and www.acme.com?

Yes, and every certificate on this page does it for you. Single-domain certificates have included the www version of the name as standard for years, so ordering for the bare domain covers both. It is worth confirming with the SSL checker after install, because serving the wrong one of the pair is a warning either way.

How many subdomains before a wildcard is cheaper than singles?

Around three, at our prices, and the crossover comes sooner if you expect to add more. The other half of the argument is administrative: one renewal date and one install instead of five, and new subdomains covered the moment they exist rather than after another order.

We are on Cloudflare. Do we still need a certificate?

Cloudflare covers the leg between your visitor and Cloudflare. The leg between Cloudflare and your origin server needs its own certificate unless you are happy with that hop unencrypted, which fails most audits. A cheap DV certificate on the origin is the usual answer, and it does not have to be the brand Cloudflare presents at the edge.

Can I get a certificate for two years?

You can buy two years of cover here, which is the longest the industry rules allow to be sold. The certificate itself is reissued inside that term to stay within the maximum lifetime a browser will accept — we handle the reissue and it is free, as all our reissues are.

What happens if my company details do not match the register?

On OV and EV that stalls the order until they do, and it is the single most common reason validation takes longer than quoted. Check that your registered name, address and telephone number match your national company register and a public directory before you order, or send them to us first and we will check them for you.

Or browse the full lists

The recommendations above are the cheapest certificate that fits each shape. These are every certificate we sell in each one, sorted so you can compare brands and warranties yourself.

Securing something that is not a website?

Firewalls, phone systems, mail servers, NAS boxes, hypervisors and switch consoles take the same certificates, but the question is different — you know what the hardware is, not what it needs. Those pages start from the equipment.

Send us the domain and we will tell you what it needs

A line about what the site does and which names it answers on is enough. We come back with the cheapest certificate that genuinely covers it — including when that is one certificate instead of the four you were about to buy, or a free one instead of anything at all. No obligation, no sales call.