Websites & Email · SSL certificates
Work out which certificate your website needs, and what it costs
Everything your customers, your staff and your inbox touch over the public internet. Two questions decide which certificate you need — what it has to cover, and how much you have to prove about who you are — and this page answers both with prices rather than an enquiry form.
- “Not secure” is a bounce, not a warningChrome and Safari label an unencrypted page in the address bar before a visitor has read a word of it. On a checkout or a contact form that is the end of the session, and you never see it in your analytics as a certificate problem.
- An expired certificate is a full-screen stopNot a subtle badge — an interstitial the visitor has to click through, and one most will not. Every certificate here can be bought for two years and reissued free in between.
- Encryption is identical at every priceDV, OV and EV all give the same key strength and the same padlock. You are paying for what the authority checked before signing, so buy the level your customers or your auditor need and not a penny more.
- One certificate usually covers more than you thinkA wildcard covers every subdomain you will ever add; a multi-domain certificate covers up to 250 unrelated names. Most people about to buy four certificates need one.
- $14.99a year for one website
- 69% offits list price of $49
- $41.96to put your company name in it
- Minutesfrom order to installed, on DV
1. What has the certificate got to cover?
This is about scope — how many names go inside the file. Get it wrong and you either pay for coverage you never use, or find out at install time that a hostname is missing and the reissue costs you an afternoon. Every website estate is one of these four shapes.
One website
acme.com + www.acme.com
A single domain, and conventionally the www version alongside it. Right for a brochure site, a blog, a landing page — anything running on one name and taking no logins or payments.
- Domain validated · issued in minutes
- $10,000 warranty
A site and every subdomain
shop. · blog. · app. · staging. — all under acme.com
One certificate covering every subdomain of the domain, including the ones you have not thought of yet, with no reissue when you add them. It works out cheaper than singles from about the third subdomain onward.
- Domain validated · issued in minutes
- Covers unlimited subdomains of the domain
- €400,000 warranty
Several separate domains
acme.com + acme.co.uk + secondbrand.com
A wildcard only stretches across one registered domain. When the sites sit on two or three different ones, each name is listed explicitly instead — and you get one renewal date to diary rather than a spreadsheet of them.
- Domain validated · issued in minutes
- 3 hostnames included, up to 247 in total
- $10,000 warranty
Several domains and their subdomains
*.acme.com + *.acme.co.uk + *.secondbrand.com
The widest coverage a single certificate can carry. It is the expensive shape, so it earns its price when the alternative is genuinely four or five certificates — an agency estate or a group of brands.
- Domain validated · issued in minutes
- Covers unlimited subdomains of the domain
- 3 hostnames included, up to 247 in total
- $10,000 warranty
2. How much do you have to prove?
All three levels give the padlock and identical encryption strength. What changes is how much the certificate authority verifies before it signs, how long that takes, and what a visitor or an auditor can find out about you from the certificate itself. Pick the level your customers need, then pick the shape above.
Domain validated (DV)
The authority checks one thing: that you control the domain. It does that with an email to an address at the domain or a DNS record, and signs within minutes. Nothing about your organisation is checked, and nothing about it appears in the certificate.
Right for: blogs, portfolios, marketing sites, staging — anything that takes neither payments nor logins.
Comodo PositiveSSL Certificate
The cheapest certificate on this site that a browser will trust without complaint, and the one most sites should be buying. Ordered and installed inside an hour.
- Domain validated · issued in minutes
- $10,000 warranty
- Free unlimited reissues for the whole term
RapidSSL Certificate
A different root and a name your host’s documentation has probably heard of. Identical encryption and the same minutes-to-issue; buy it if something in your stack specifies the brand.
- Domain validated · issued in minutes
- $10,000 warranty
- Free unlimited reissues for the whole term
Organisation validated (OV)
The authority checks that your registered company exists, that it is reachable at a published number, and that it controls the domain, then writes the company name into the certificate. One to three working days, and you will get a phone call.
Right for: company sites, customer portals, staff logins, B2B — anywhere a security questionnaire is going to land.
Certum Trusted SSL Certificate (OV)
The cheapest way to get a vetted company name inside a certificate. For most businesses that name is the whole reason to move off DV, and there is no need to pay half as much again for it.
- Organisation validated · issued in 1-3 days
- $10,000 warranty
GeoTrust True BusinessID SSL Certificate
The same organisation vetting with a far larger warranty behind it, and the GeoTrust name. Buy it when a contract or an insurer specifies a warranty figure rather than a validation level.
- Organisation validated · issued in 1-3 days
- $1,250,000 warranty
- Free unlimited reissues for the whole term
Extended validation (EV)
Legal, physical and operational existence of the business, checked against public records under the strictest rules the industry defines. Three to seven working days, and longer if your registry entry is out of date.
Right for: checkouts, payments, fintech, banking, healthcare — anywhere money or medical data changes hands.
Certum Premium EV SSL Certificate
Full EV vetting at roughly two-thirds off what the mainstream brands charge for it. If you need EV because a policy says EV, this satisfies the policy.
- Extended validation · issued in 7 days
- €1,000,000 warranty
True BusinessID with Green Bar EV
The same EV vetting, faster, from a brand procurement teams recognise, and with the biggest warranty on this page behind it.
- Extended validation · issued in 1-5 days
- $1,500,000 warranty
- Free unlimited reissues for the whole term
3. Email
Email splits into two different problems that get asked about as one question, and they need different certificates. One is issued to a person and travels with the message; the other is issued to hostnames and lives on the server.
Signing and encrypting the messages
An S/MIME certificate is issued to a person, not to a domain. It signs outgoing mail so a recipient can prove it genuinely came from you, encrypts the body so only they can read it, and doubles as a client certificate for logging in to portals and VPNs without a password. One per mailbox.
Typically: finance teams, legal, anyone whose signature on an email has to mean something.
CPAC Basic - Personal Authentication Signature
Proves control of the address and signs and encrypts from any normal mail client. The right starting point unless your name specifically has to appear in the certificate.
- Email Validation
- Installs in Outlook, Apple Mail, Thunderbird and mobile
- Also works as a client certificate for portal and VPN logins
- Issued to one mailbox — buy one per person
Certum Professional ID (S/MIME)
Your verified full name goes inside the certificate as well as the address, which is what a counterparty checks when a signature has to carry legal weight.
- Identity Validation · issued in 1-3 days
- $4,000 warranty
- Your identity checked against documents before issue
- Recognised for signing PDFs as well as email
Securing the mail server itself
Your mail server answers on more names than anyone expects — mail., smtp., imap., webmail. and, on Exchange, autodiscover. Miss one and Outlook prompts every user every morning until somebody works out why. That is a multi-domain job.
Typically: Exchange, Microsoft 365 hybrid, Zimbra, MDaemon, Postfix and cPanel mail.
Comodo PositiveSSL Multi-Domain Certificate
Three hostnames included and room for far more, which is normally enough for mail, autodiscover and webmail on one file. Add the rest at checkout.
- Domain validated · issued in minutes
- 3 hostnames included, up to 247 in total
- $10,000 warranty
- Free unlimited reissues for the whole term
Running Exchange, Zimbra or a hybrid tenant and want the hostname list worked out for you? That is covered in detail on the mail servers and webmail page.
What the wrong certificate — or no certificate — actually costs
Not an abstraction. These are the four things that go wrong on websites, in the order people usually notice them.
- Visitors leave before the page finishes loading “Not secure” sits in the address bar of every unencrypted page, and an expired certificate gets a full-screen interstitial. Neither shows up in analytics as a certificate problem — it shows up as a bounce rate you cannot explain.
- The name on the certificate does not match the name in the browser Buying for acme.com and serving www.acme.com, or covering the domain but not the subdomain the app runs on, produces exactly the same warning as having no certificate at all. This is the single most common mistake, and the four shapes above exist to prevent it.
- Search and payment providers treat it as a signal HTTPS has been a ranking factor for years, card processors expect it on anything touching a payment flow, and browsers withhold modern APIs from insecure origins. None of that is negotiable per-site.
- Renewal comes round and nobody owns it Certificates lapse on a Saturday, at whatever hour they were issued. Consolidating an estate onto one wildcard or one multi-domain certificate replaces five diary entries with one, which is usually the real argument for buying the wider shape.
Three things worth knowing before you order
EV no longer turns the address bar green
Extended validation certificates used to paint the address bar green with your company name in it. Every major browser removed that treatment years ago, so to a casual visitor an EV certificate now looks identical to a $15 one. It still means something — the vetting is real, the warranty is much larger, and the organisation details are inspectable in the certificate — but if you are buying EV for a visible green bar, you will not get one. Buy it because a policy, an auditor or a contract asks for it.
A wildcard covers one level, not all of them
A certificate for *.acme.com covers shop.acme.com and blog.acme.com, and it does not cover eu.shop.acme.com — the star matches a single label. Most estates never hit this; the ones that do are usually running regional or per-customer subdomains. If yours is one of them, a multi-domain wildcard or a second wildcard for the deeper level is the fix, and it is much cheaper to establish that now than after issue.
Sometimes a free certificate is the right answer, and we will say so
If your site is on a host that issues and renews Let's Encrypt certificates for you, your server can reach the internet on port 80, and nobody needs your company name inside the certificate, a free one is genuinely fine and you should use it. People buy here when the site is not internet-facing, when they want a one or two year cycle instead of renewing every ninety days, when one certificate has to cover a whole estate, or when they need organisation or extended validation — which no free authority issues. Ask us first if you are unsure; we would rather lose the sale than sell you something you did not need.
What comes with the price
- Lowest price guaranteeFind the same certificate cheaper anywhere and we match it.
- 10-day money backOn SSL certificates: cancel inside 10 days for a full refund. Email signing certificates are not covered. Read the policy.
- Free unlimited reissuesChange a hostname or move host mid-term at no cost.
- Free installation supportStuck on cPanel, IIS or a load balancer? Our engineers finish it with you.
- Issued by the authority itselfSectigo, Comodo, GeoTrust, Thawte, RapidSSL or Certum sign it — not us. Same certificate, lower price.
- Free tools, no sign-upCSR generator, checker, decoder and four more.
How the install actually goes
Three steps, and the same three whether the site is on cPanel, IIS, Nginx or a load balancer.
- Generate the request on the server Most control panels will create the signing request themselves and keep the private key on the box, which is safer than moving a key around. Where one cannot, our free CSR generator makes the request and gives you the matching key. Check it with the CSR decoder before you submit it — a typo in the domain costs a reissue.
- Order and validate Paste the request in at checkout. Domain validation is an email to an address at the domain or a DNS record and takes minutes; organisation validation adds a company check of one to three working days, extended validation three to five.
- Install the certificate and its chain This is where installs go wrong. Desktop browsers often forgive a missing intermediate; mobile browsers, mail clients and API integrations do not, so the site looks fine to you and broken to a quarter of your visitors. Confirm it from outside with the SSL checker, and if a certificate and key will not pair, the key matcher says why in seconds. Then redirect http to https so nobody lands on the unencrypted version.
Questions we get asked before people order
Does a more expensive certificate encrypt better?
No. A $15 DV certificate and a $2,000 EV certificate negotiate exactly the same ciphers and the same key strength. Everything you pay above the cheapest is buying vetting, warranty and brand — not security on the wire. Anyone who tells you otherwise is selling.
Do I need to cover both acme.com and www.acme.com?
Yes, and every certificate on this page does it for you. Single-domain certificates have included the www version of the name as standard for years, so ordering for the bare domain covers both. It is worth confirming with the SSL checker after install, because serving the wrong one of the pair is a warning either way.
How many subdomains before a wildcard is cheaper than singles?
Around three, at our prices, and the crossover comes sooner if you expect to add more. The other half of the argument is administrative: one renewal date and one install instead of five, and new subdomains covered the moment they exist rather than after another order.
We are on Cloudflare. Do we still need a certificate?
Cloudflare covers the leg between your visitor and Cloudflare. The leg between Cloudflare and your origin server needs its own certificate unless you are happy with that hop unencrypted, which fails most audits. A cheap DV certificate on the origin is the usual answer, and it does not have to be the brand Cloudflare presents at the edge.
Can I get a certificate for two years?
You can buy two years of cover here, which is the longest the industry rules allow to be sold. The certificate itself is reissued inside that term to stay within the maximum lifetime a browser will accept — we handle the reissue and it is free, as all our reissues are.
What happens if my company details do not match the register?
On OV and EV that stalls the order until they do, and it is the single most common reason validation takes longer than quoted. Check that your registered name, address and telephone number match your national company register and a public directory before you order, or send them to us first and we will check them for you.
Or browse the full lists
The recommendations above are the cheapest certificate that fits each shape. These are every certificate we sell in each one, sorted so you can compare brands and warranties yourself.
- Single-domain SSL One name, plus its www — issued in minutes The whole of the cheap end of the market, sorted by price. Everything here proves control of the domain and nothing about your company, which is the right trade for a site that takes no logins and no payments. See the certificates and prices →
- Wildcard SSL *.yourdomain.com — unlimited subdomains One file that covers shop., blog., app., staging. and whatever you add next year without a reissue. It stops paying for itself somewhere around the third subdomain, and it is the usual answer for anyone running more than a homepage. See the certificates and prices →
- Multi-domain (SAN) SSL Up to 250 unrelated domains on one certificate A wildcard only stretches across one registered domain. When the estate spans two or three, each name is listed explicitly instead — and you get one renewal date to diary rather than five. See the certificates and prices →
- Multi-domain wildcard Several domains, each with all its subdomains The widest coverage a single certificate can carry. It is the expensive shape, so buy it when the alternative is genuinely four or five certificates — an agency estate or a group of brands, not a single site with a staging box. See the certificates and prices →
- Organisation validated (OV) Your registered company name inside the certificate The authority checks that your company exists and controls the domain, then writes the company name where an auditor or a customer can read it. Most enterprise security reviews expect at least this on anything with a login. See the certificates and prices →
- Extended validation (EV) Legal, physical and operational checks The strictest vetting the industry defines, and the largest warranties. Browsers stopped showing it differently years ago, so buy it for what it proves in an audit rather than for anything a visitor will notice. See the certificates and prices →
Securing something that is not a website?
Firewalls, phone systems, mail servers, NAS boxes, hypervisors and switch consoles take the same certificates, but the question is different — you know what the hardware is, not what it needs. Those pages start from the equipment.
- Firewalls, VPN & routers FortiGate, SonicWall, Palo Alto, pfSense, Cisco ASA
- Voice: PBX, UCM & SBC Cisco UCM, 3CX, FreePBX, session border controllers
- Mail servers & webmail Exchange, autodiscover, Zimbra, smtp, imap
- Intranet & internal apps Staff portals, Jira, GitLab, dashboards, RDS
- NAS, hypervisor & consoles Synology, QNAP, VMware, Proxmox, iLO, iDRAC
- Web & app servers IIS, Apache, Nginx, Tomcat, load balancers
Send us the domain and we will tell you what it needs
A line about what the site does and which names it answers on is enough. We come back with the cheapest certificate that genuinely covers it — including when that is one certificate instead of the four you were about to buy, or a free one instead of anything at all. No obligation, no sales call.