October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Certbot

How to Get a Free SSL Certificate for Your WordPress Website

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For most WordPress sites, the easiest way to get free HTTPS is to enable your host’s built-in Let’s Encrypt option. The host’s ACME client requests the certificate, installs it, and renews it. If your host does not offer managed SSL, you can use Certbot on your own Apache or Nginx server, or use DNS-01 validation when port 80 is unavailable or you need a wildcard certificate.

What a free SSL certificate means

Let’s Encrypt is a free certificate authority that issues TLS certificates through the automated ACME protocol. Certbot is free, open-source software that can request Let’s Encrypt certificates and, with the appropriate plugin, configure Apache or Nginx.

The certificate itself costs nothing, but you still pay for any domain registration, hosting, DNS service, administration, premium support, or managed certificate product you choose. A free certificate also needs successful renewal; an expired certificate can make a working WordPress site appear offline or unsafe.

WordPress is compatible with HTTPS once a TLS certificate is installed and available to the web server. WordPress.org’s current requirements baseline lists HTTPS as required for every installation (page accessed September 30, 2026).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the right installation path

Option Access needed Validation and renewal Best for
Hosting-managed HTTPS Hosting dashboard or support ticket Usually automatic ACME validation and renewal Most site owners who want the least maintenance
Certbot on Apache or Nginx SSH plus administrative server access HTTP, DNS, or standalone challenge; you must verify the renewal job Self-managed virtual servers and dedicated servers
DNS-01 validation Ability to edit authoritative DNS TXT record under _acme-challenge; supports automated DNS plugins or manual hooks Blocked port 80, off-server issuance, and wildcard certificates

Path A: Enable HTTPS in managed WordPress hosting

  1. Point the domain to the WordPress host. Confirm that the apex domain and any hostname you will use, such as www, resolve to the correct server.
  2. Find the SSL control. In the host dashboard, look for labels such as SSL/TLS, HTTPS, Let’s Encrypt, or Security certificate. Some hosts enable it automatically after DNS is correct.
  3. Request or enable the certificate. Select every hostname that serves your site. If the option is missing, ask support whether the plan includes Let’s Encrypt issuance and automatic renewal. If it does not, use a host that provides full HTTPS support.
  4. Wait for issuance and installation. The host’s ACME client performs domain validation and places the certificate on the web server. Do not change WordPress URLs until the HTTPS virtual host responds correctly.
  5. Turn on the HTTP-to-HTTPS redirect. Use the host’s redirect control when available. This sends visitors from http:// to https:// and prevents two address versions from being indexed or cached separately.
  6. Set WordPress URLs to HTTPS. In the dashboard, open Settings > General and change both WordPress Address (URL) and Site Address (URL) to the HTTPS versions. Save only after the secure site works.
  7. Check renewal. Confirm that the panel shows an active renewal schedule. For a business-critical site, also use an independent certificate-expiry monitor and record who owns renewal failures.

Path B: Use Certbot on Apache or Nginx

Use this route only when you control the server and its web configuration. You need administrative access, a functioning Apache or Nginx installation, DNS pointing to that server, and firewall rules that permit the chosen validation method.

Request and install a certificate

Install Certbot using the method recommended for your server’s operating system. Then request certificates for the exact names that serve traffic, commonly the apex domain and www. Certbot can obtain and install a certificate in one operation, or you can use certonly when you intend to edit the virtual host yourself.

A typical web-server flow is conceptually:

certbot --apache -d example.com -d www.example.com
certbot --nginx -d example.com -d www.example.com

Use the plugin matching your server, and replace the example names with your domains. The command may alter the virtual host and offer to add an HTTP-to-HTTPS redirect; review the proposed changes before accepting them.

When HTTP validation is appropriate

Webroot, Apache, Nginx, and standalone HTTP-01 flows generally require Let’s Encrypt to reach your site through public TCP port 80. Ensure DNS, firewall rules, load balancers, and proxy settings allow that connection. A server that only accepts HTTPS on port 443 can fail HTTP-01 validation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test and schedule renewal

  1. Open the HTTPS site and verify that the expected virtual host and certificate are returned.
  2. Reload Apache or Nginx after configuration changes.
  3. Run Certbot’s renewal simulation, commonly certbot renew --dry-run, and inspect the system timer or scheduled job that will run renewal.
  4. Check that the web server reloads after a successful renewal so it begins using the new certificate.

Manual HTTP or DNS challenges do not renew by themselves unless you add deploy or authentication hooks. Choose an auto-renewing plugin or deliberately repeat the challenge before expiry.

Use DNS-01 when port 80 is blocked or you need a wildcard

DNS-01 proves control by requiring a TXT record at a name such as _acme-challenge.example.com. Certbot provides the value; create it at the authoritative DNS provider, wait for propagation, and let validation complete. This method does not require Let’s Encrypt to connect to the web server on port 80.

DNS-01 is also the validation method that supports wildcard certificates, such as *.example.com. A DNS plugin can create and remove TXT records automatically, but it requires narrowly scoped API credentials. If you use a manual DNS challenge, document the procedure and add hooks or repeat it for every renewal.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Finish the WordPress HTTPS configuration

Force secure administrator sessions when appropriate

After the secure virtual host is working, you can add define('FORCE_SSL_ADMIN', true); to wp-config.php. WordPress advises configuring SSL on the server first; enabling this constant before HTTPS works can lock you out of the dashboard.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix mixed content

Open the browser developer console and identify images, scripts, stylesheets, fonts, API calls, canonical tags, or embedded frames still loaded over http://. Update the responsible WordPress setting, theme, plugin, or database URL to HTTPS. Do not blindly replace every database value without a backup, because serialized plugin data can be corrupted by unsafe search-and-replace operations.

Test the whole site

  • Log in and log out of WordPress.
  • Submit contact, search, membership, and checkout forms.
  • Check redirects for both the apex and www hostnames.
  • Verify caching, CDN, reverse-proxy, and image-optimization layers use HTTPS at every hop.
  • Confirm that the certificate’s subject or SAN list covers every hostname visitors actually use.
  • Inspect payment and other sensitive pages for secure requests and correct return URLs.

Common problems and the practical fix

The host has no SSL button

Ask support whether Let’s Encrypt is available on your plan and whether renewal is automatic. If the answer is no, either manage the server with Certbot or move the site to hosting that includes complete HTTPS support.

HTTP-01 validation fails

Check that the domain resolves to the requesting server, port 80 is publicly reachable, no firewall or proxy intercepts the challenge path, and another web server is not answering for the hostname. Use DNS-01 when the architecture cannot expose port 80.

The certificate is valid but the browser still warns

Confirm that the certificate covers the exact hostname in the address bar, that the server sends the correct certificate chain, and that the page is not loading active resources over HTTP. Clear cached redirects only after correcting the server configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Renewal failed

Read the ACME client log, then check DNS, firewall access, challenge records, rate-limit messages, and the renewal timer. Restore the original validation path or add the required DNS or deploy hook. Renew before the current certificate expires and verify the web server reload afterward.

How to keep a free certificate reliable

  • Keep DNS records, server access, and ACME credentials documented.
  • Limit DNS API keys to the required zone and permissions.
  • Monitor certificate expiry independently of the host dashboard.
  • Test renewal after moving hosts, changing proxies, or modifying firewall rules.
  • Keep WordPress, themes, plugins, and the operating system updated so HTTPS configuration is not undermined by vulnerable software.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.