Free SSL Certificates: How AutoSSL and SSL/TLS Status Work

Every hosting account includes free SSL certificates, so your website loads over HTTPS with a padlock. They're issued and renewed automatically by cPanel's AutoSSL feature. This guide explains how free SSL with AutoSSL works, how to check your coverage on the SSL/TLS Status page, and what to do when a certificate isn't issued.

How AutoSSL works

  • AutoSSL checks your account regularly and requests a free domain-validated (DV) certificate for your domain and its subdomains, such as www, mail, webmail and cpanel.
  • Before issuing, the certificate authority confirms that each name really points to the Instant Access Internet Services server. This is called domain control validation (DCV).
  • Certificates are short-lived (typically 90 days) and are renewed automatically well before they expire. You don't need to do anything.
  • A new domain or subdomain is usually covered within a few hours of being added and pointed to our nameservers.

The free certificate works in every modern browser. It's the same type of certificate many paid "basic" SSL products provide. You only need to buy one if you want an organization-validated (OV) or extended-validation (EV) certificate.

Check your SSL coverage

  1. In cPanel, go to Security > SSL/TLS Status.
  2. Review the list of domains. Each one shows an icon for its certificate status, for example an AutoSSL domain-validated certificate, a self-signed certificate, or unsecured.
  3. Click Show Unsecured Domains to see only the names that aren't covered.
  4. If a domain has a problem, the Certificate Status column shows the AutoSSL error message for it.

How soon will a new name be covered?

AutoSSL runs automatically several times a day, so there's no button to start it yourself. If you've just added a subdomain or fixed a DNS problem, wait a few hours and check the SSL/TLS Status page again. If a name is still unsecured after a day, read its error in the Certificate Status column (see Troubleshooting below) or open a ticket.

Include or exclude domains

By default AutoSSL covers everything. You can stop it from covering a name, for example if you installed a certificate you bought.

  1. On the SSL/TLS Status page, tick the checkbox next to the domain(s).
  2. Click Exclude from AutoSSL. To reverse it later, select them again and click Include during AutoSSL.

Don't exclude names unless you have a reason. An excluded name won't get a certificate and will show a browser warning over HTTPS.

Troubleshooting AutoSSL

"DNS DCV" or "HTTP DCV" errors

The name doesn't point to our server. Check that your domain uses our nameservers (Our Nameservers: How to Point Your Domain to Your Hosting), or, if your DNS is elsewhere, that the A records point to your account's IP. Recently changed DNS may still be propagating (DNS Propagation: Why Domain Changes Take Time and How to Check).

Subdomains like www or mail aren't covered

Each name must resolve on its own. If you manage DNS elsewhere, make sure www and mail records exist. Names that don't resolve at all (for example a cpcalendars name you never added) simply get skipped. That's fine and doesn't affect your website.

You use Cloudflare or another proxy

If the proxy is on (orange cloud), validation requests may never reach us. Use Cloudflare's "Full (strict)" SSL mode and, if AutoSSL still fails, turn the proxy off (grey cloud) until the certificate shows as issued on the SSL/TLS Status page, usually within a few hours, then turn it back on.

Redirects or security rules block validation

The certificate authority fetches a small file from /.well-known/ on your site. Custom .htaccess rules, security plugins or a "coming soon" page that redirects everything can block it. Make sure requests to /.well-known/ are not redirected or blocked. A normal HTTP-to-HTTPS redirect is fine.

A CAA record blocks the certificate authority

If you've added a CAA record in the Zone Editor, it must allow the certificate authority AutoSSL uses. If you aren't sure, remove the CAA record or open a ticket.

I have a certificate but still see "Not Secure"

That's usually mixed content (images or scripts loaded over http://) or the site not being forced to HTTPS. See How to Fix "Not Secure" Warnings and Mixed Content Errors and How to Force HTTPS on Your Website.

Related guides

Still stuck? Open a support ticket and the Instant Access Internet Services team will help.

Ultrafast LiteSpeed hosting from InstantAccess.net: free SSL, free backups, cPanel included, no contracts. Check out our $10/month hosting.
  • free ssl cpanel, autossl, cpanel ssl/tls status, autossl not issuing certificate, autossl not working, ssl certificate expired cpanel, https certificate free
  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

How to Use Microsoft 365 or Google Workspace Email with Your Domain

You can keep your website with us and use Microsoft 365 (Outlook) or Google Workspace (Gmail) for...

Our Nameservers: How to Point Your Domain to Your Hosting

To make your website and email work on your hosting account, your domain has to point to the...

DNS Propagation: Why Domain Changes Take Time and How to Check

When you change your nameservers or edit a DNS record, some people see the change right away...

How to Set Up Dynamic DNS in cPanel

Dynamic DNS (DDNS) lets you reach a device on a home or office connection, such as a camera, NAS...

How to Install an SSL Certificate You Bought in cPanel

Your Instant Access Internet Services account already gets free SSL through AutoSSL, but if you...