Encryption isn't
a premium feature.
Every site here gets a wildcard certificate covering your domain and every subdomain under it. Issued in seconds, renewed every 90 days, and it costs nothing — because charging for HTTPS in 2026 is charging for the floor.
Every InstaHost plan includes a free wildcard SSL certificate covering your domain and all of its subdomains. It is issued automatically through Let's Encrypt the moment a site is created, renews itself every 90 days, and applies to unlimited sites and aliases. There is no certificate signing request to generate, nothing to upload and no installation step.
A free domain-validated certificate uses identical cryptography to a paid one and produces an identical padlock. OV and EV certificates are available on request where a procurement process demands them — and we'll tell you plainly when it doesn't.
Wildcard, not single-name
One certificate covers www, shop, staging, api and anything you add later. Sold elsewhere for around £99 a year.
See the coverage →Issued in seconds
Validation happens over HTTP automatically. No CSR, no key file, no pasting certificate blocks into a control panel.
How issuance works →Renewed without you
Every 90 days, well before expiry — and expiry is monitored, so a failed renewal wakes an engineer, not your customers.
The renewal loop →The cert isn't the defence
HTTPS encrypts traffic in transit. It stops nothing else. Here's the rest of what's actually guarding the site.
The security stack →Two of these columns
are the same product.
Certificate types differ in what the authority checked before issuing — not in how strongly they encrypt. Every row below is verifiable in about a minute, which is rather the point.
| Free DV Yours, included | Paid DV | OV | EV | |
|---|---|---|---|---|
| Encryption | Identical | Identical | Identical | Identical |
| Padlock in browser | Yes | Yes | Yes | Yes |
| Company name shown | No | No | No | Green bar — removed 2019 |
| What was verified | Control of the domain | Control of the domain | Domain + company exists | Domain + vetted legal entity |
| Time to issue | Seconds | Minutes | 1–3 days | 1–2 weeks |
| Covers subdomains | Yes — wildcard | Usually extra | Usually extra | Rarely |
| Worth buying when | Always. It's included. | Never, honestly | Procurement demands it | An auditor names it |
| Typical price elsewhere | — | £49.99/yr | £99/yr | £275/yr |
We could sell you a £49.99 DV certificate.
It would be byte-for-byte as secure as the free one already on your site, issue a little slower, and cover fewer names. Some hosts still sell exactly that, alongside a line about the green bar that browsers stopped drawing seven years ago. We'd rather explain the difference and hand you the wildcard.
One certificate. Every subdomain.
Including the ones that don't exist yet. Add a staging site next March and it's already covered — no reissue, no request, no charge.
Nothing for you to do. Ever.
The traditional SSL process involves a signing request, a private key, an intermediate bundle and a control panel form. None of that happens here.
- You add a site That's the trigger. No separate SSL step, no product to order, no box to tick at checkout.
- We prove the domain Validation runs over HTTP against Let's Encrypt automatically. Takes seconds, needs nothing from you.
- HTTPS goes live The wildcard is installed and the site is served over TLS from the moment it's reachable.
- It renews itself Every 90 days, well ahead of expiry. Expiry is monitored too, so a failure alerts an engineer.
A certificate stops eavesdropping.
It stops nothing else.
HTTPS protects data in transit. It does not stop an injection attempt, a credential-stuffing run or a malware upload. These do — and none of them is a paid add-on.
Renewable since 1996.
Every TLS handshake costs a little electricity, and there are a great many of them. Worth knowing where it comes from.
Straight answers.
Do I have to pay for SSL here?
No. A wildcard certificate is included on every plan, covering your domain and every subdomain. Issued automatically via Let's Encrypt, renewed every 90 days, unlimited sites and aliases. No CSR, no upload, no installation step.
Is free SSL as secure as paid SSL?
For encryption — identically. Free DV and paid DV use the same cryptography, the same key lengths and the same TLS protocols, and draw the same padlock. What differs between certificate types is what the authority checked before issuing, not the strength of the connection.
Anyone selling a paid DV certificate on the grounds that it's "more secure" is describing something that isn't true.
What is a wildcard certificate?
One certificate covering a domain and all its subdomains — www, shop, mail, staging, api, and anything added later. Without one, every subdomain needs its own.
Wildcards are commonly sold at around £99/yr. Here the free certificate is the wildcard.
What happened to the green address bar?
Browsers removed it. Chrome dropped the EV indicator in version 77 (September 2019), Firefox in version 70 a month later, Safari earlier still.
An EV certificate still contains the verified company details — but no mainstream browser shows them to a visitor. The address bar looks identical to a free certificate's. Providers still selling EV on the green bar are selling a thing browsers stopped drawing years ago.
What's the difference between DV, OV and EV?
What was verified — not encryption strength. DV proves domain control, issues in seconds. OV also checks the company exists on record. EV applies stricter documented vetting of the legal entity.
All three encrypt identically and show an identical padlock. OV and EV earn their keep when a procurement process, insurer or auditor names them specifically — and rarely otherwise.
How fast is it issued?
Seconds. The request fires as soon as a site is added, and validation runs over HTTP with no action from you. Sites are served over HTTPS from the moment they're live.
Does it renew automatically?
Yes — every 90 days, well before expiry. Let's Encrypt certificates have a 90-day lifetime by design. Expiry is monitored as part of the platform, so a failed renewal raises an alert to our engineers rather than becoming an outage a customer tells you about.
Do I need your nameservers?
It's the simplest route and what we'd recommend — validation and renewal then happen entirely our side. Sites on external nameservers can still be secured, but the domain must resolve to our platform for HTTP validation to complete. Keep the A record accurate and renewals keep working.
Can I still buy OV or EV?
Yes, on request. Some organisations have a procurement or compliance requirement naming OV or EV, and we'll source and install one where that's the case.
We'll also say plainly when we think you don't need it — for the overwhelming majority of sites the free wildcard does exactly the same job in the browser.
Does HTTPS help my search rankings?
It's a confirmed ranking signal, though a light one, and has been since 2014. The bigger effect runs the other way: browsers mark plain HTTP as "Not secure" and Chrome warns on mixed content. HTTPS isn't an advantage now — it's the baseline, and lacking it is the penalty.
What else protects my site?
A certificate encrypts traffic in transit; it stops nothing else. Also included: a web application firewall (SQL injection, XSS, path traversal, under a millisecond at the edge), 1 Tbps+ DDoS scrubbing, daily malware scanning, brute-force protection, 2FA on panel and SSH, and 30-day backups. The full stack →
Are you certified for information security?
Data centres hold ISO 27001 for information security and ISO 14001 for environmental management, are PCI compliant and staffed around the clock. Running on 100% renewable energy since 1996.
Your certificate is already waiting.
Every plan includes the wildcard. Move a site over and HTTPS is live before you've finished checking the DNS — and it stays live without you thinking about it again.