Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The simplest way to get HTTPS for free is to enable your hosting provider’s built-in SSL option. Most managed hosts can issue and renew a Domain Validation (DV) certificate automatically. If your host does not, use Let’s Encrypt with an ACME client such as Certbot, or place the site behind Cloudflare and use its Universal SSL certificate. Whichever route you choose, the job is not finished until the certificate is installed, HTTP redirects to HTTPS, mixed content is fixed, renewal is tested, and the connection from the proxy to your origin is protected.

What a free SSL certificate actually does

“SSL” is the common name for the technology now called TLS. A certificate lets a browser verify that a server controls a domain and negotiate an encrypted HTTPS connection. The free choices covered here are Domain Validation (DV): the certificate authority verifies control of the domain, not your company’s legal identity or physical address.

Getting a certificate and making a site fully HTTPS are separate tasks. You must install the certificate and private key, serve the complete certificate chain, make port 443 reachable, redirect HTTP traffic, remove insecure asset references, and arrange renewal before expiry.

Choose the right free route

Route Best for Main setup work Important limitation
Hosting-provider HTTPS Beginners and managed sites Enable the host’s SSL/HTTPS setting and verify coverage Automation and hostname coverage vary by provider
Let’s Encrypt plus an ACME client VPS and server operators Install a client, pass a domain-control challenge, configure the web server, automate renewal Requires administrative access and correct DNS/network access
Cloudflare Universal SSL Sites willing to proxy DNS traffic through Cloudflare Activate the domain, proxy hostnames, choose an encryption mode, enforce HTTPS Cloudflare’s edge and your origin are separate TLS connections

Start with your host

Let’s Encrypt and Certbot both advise checking whether the hosting company already manages certificates. In a control panel, look for labels such as SSL, TLS, HTTPS, or Let’s Encrypt. Enable the feature, then verify the apex domain (for example, example.com) and every required hostname such as www.example.com are listed. This route normally has the least maintenance because issuance and renewal are handled for you.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use Let’s Encrypt when you control the server

Let’s Encrypt is a certificate authority operated by the nonprofit Internet Security Research Group. It provides free TLS certificates, but an ACME client is required to communicate with its API. Certbot is the commonly recommended client and can obtain a certificate and configure supported Apache or Nginx installations.

Prerequisites

  • DNS for each requested hostname points to the intended server.
  • You have administrator or equivalent privileges on that server.
  • Port 443 is reachable for normal HTTPS traffic.
  • For an HTTP-01 challenge, port 80 is reachable from the public internet and is not blocked by a firewall, load balancer, or redirect rule that prevents validation.
  • You know whether another service already terminates TLS (such as a load balancer or CDN).

The operational sequence

  1. Confirm DNS records and decide which names belong on the certificate.
  2. Install the ACME client supplied for your operating system. Use the client’s official installation instructions rather than copying an unrelated package command.
  3. Choose a challenge supported by your environment: HTTP-01, TLS-ALPN-01, or DNS validation.
  4. Complete the challenge. Let’s Encrypt issues the certificate only after you demonstrate control of the domain.
  5. Configure your web server to present the certificate, private key, and intermediate chain on port 443.
  6. Enable the client’s renewal timer or scheduled task.
  7. Run a renewal dry run or staging test where supported, before the first certificate approaches expiration.
  8. After HTTPS works, redirect HTTP requests and repair mixed-content references.

Which challenge should you use?

  • HTTP-01: the client publishes a temporary token over HTTP. It is straightforward, but the authority must reach port 80.
  • TLS-ALPN-01: validation occurs during a special TLS handshake. It can avoid serving a token over HTTP but requires control of the TLS listener.
  • DNS-01: the client proves control by creating a DNS record. It is useful when inbound web ports cannot be reached and is required for many wildcard-certificate setups, but DNS API credentials must be protected.

Do not manually copy a certificate into production and assume the job is complete. The private key must remain secret, the full chain must be served, and renewal must update the active web-server configuration.

Use Cloudflare Universal SSL correctly

Cloudflare says it issues and renews free, unshared, publicly trusted certificates for domains added to and activated on its service. Universal SSL is an edge certificate: it protects the visitor-to-Cloudflare connection when the hostname is proxied. It is DV, so it confirms domain control rather than organizational identity.

  1. Add the domain to Cloudflare and complete the required DNS delegation.
  2. Proxy the hostnames that should receive the edge certificate. Cloudflare’s standard full DNS setup covers the zone apex and first-level subdomains; confirm your exact names in the dashboard.
  3. Choose an encryption mode in the SSL/TLS settings.
  4. For Full (strict), install a valid, unexpired certificate on the origin server. Cloudflare documents a free Origin CA certificate for the Cloudflare-to-origin connection.
  5. Enable an HTTPS redirect or equivalent redirect rule. Merely having an edge certificate does not redirect every HTTP request.
  6. Test application resources and APIs for mixed content and origin failures.

Think of Cloudflare as two connections: visitor to Cloudflare and Cloudflare to your origin. An edge certificate alone does not prove that the origin is encrypted or authenticated. Full (strict) is the appropriate mode when the origin has a valid certificate whose names match the hostname.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make the site fully HTTPS after issuance

Verify names and chain

  • Inspect the certificate’s Subject Alternative Names and confirm the apex, www, and every required subdomain are present.
  • Check the expiration date and that the complete intermediate chain is sent.
  • Resolve DNS and confirm it points to the server or proxy where the certificate is installed.
  • Connect to the public HTTPS URL and confirm port 443 is reachable.

Redirect HTTP safely

Once the HTTPS endpoint works, issue a permanent redirect from HTTP to HTTPS at the web server, load balancer, or CDN. Test both the bare domain and www form, and check that redirects do not loop when Cloudflare or another proxy is in front of the origin.

Remove mixed content

Search templates, stylesheets, scripts, fonts, images, API endpoints, canonical URLs, and embedded frames for absolute http:// references. Replace them with HTTPS or protocol-relative application settings where appropriate. Browser developer tools identify resources that are blocked or merely upgraded.

Test renewal, not just installation

Find the ACME client’s timer, cron job, or host-managed renewal status. Run a dry run or staging renewal supported by the client. Confirm that a renewed certificate is reloaded by the web server and that monitoring will alert you before expiry.

Troubleshooting common failures

“The certificate does not cover this hostname”

The requested name was omitted, or DNS sends traffic to a different endpoint. Request a certificate containing every required name and install it on the server actually serving that name.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HTTP-01 validation times out

Port 80 may be blocked, DNS may be stale, or a proxy may be intercepting the challenge path. Open the port, correct DNS, and ensure the ACME token reaches the client’s web root. Use DNS-01 if inbound HTTP cannot be made reachable.

Browser reports an incomplete chain

The server is sending only the leaf certificate. Configure the full-chain file supplied by the client and reload the web server. Do not send the private key to the browser.

Cloudflare shows an origin error

In Full (strict), the origin certificate may be expired, self-signed, issued for another name, or not reachable on the configured port. Install a valid matching origin certificate, correct the port, and verify firewall rules.

Redirect loop after enabling HTTPS

A proxy may be forwarding HTTP to the origin while the origin redirects back to HTTPS without honoring the proxy’s forwarded-protocol header. Align the proxy encryption mode and application URL settings, then test each hop.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Adams Gift Certificate Book, Carbonless, Single Paper, 3.4 x 8 Inches, White/Canary, 2-Part, 25 Numbered Certificates Plus Store Sign (GFTC1)
  • 2-part carbonless unit set
  • Consecutive numbering
  • Includes Gift Certificates Available sign
  • 25 certificates with envelopes per package
  • White/canary form sequence

Some page elements remain insecure

Mixed content commonly comes from hard-coded asset URLs, third-party widgets, or API calls. Update those references or replace providers that do not support HTTPS.

Renewal works manually but not automatically

The scheduled job may run under a different user, lack DNS API permission, or fail to reload the web server. Inspect the job logs, grant only the required permissions, and test the complete unattended path.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If you need screenshots to verify that the HTTPS page renders correctly, ScreenshotNeo can capture the URL through one API request. It accepts cookie or consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result. Its MCP server includes take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.

See the complete parameter reference in the ScreenshotNeo documentation. Example:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Equivalent Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Equivalent Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo includes full-page capture, device and retina settings, waits, custom headers and cookies, request blocking, caching, signed links, PDFs, async jobs, bulk capture, and an OpenAPI spec. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account to check your HTTPS pages without setting up a browser.

FAQ

Do I need Certbot?

No. Use Certbot when your host does not manage certificates and you control a compatible server. A different ACME client can work equally well.

Is a free DV certificate suitable for an online store?

DV encrypts traffic and authenticates the domain. It does not identify the organization; choose certificate assurance based on your legal, regulatory, and customer requirements.

Can I use a certificate on both the apex and www hostnames?

Yes, but both names must be included in the certificate and routed to the endpoint presenting it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does Cloudflare Universal SSL encrypt traffic to my server?

Only if the Cloudflare-to-origin connection is configured for HTTPS. Full (strict) requires a valid origin certificate.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.