--- title: "\"Wildcard SSL: One Certificate for Every Subdomain You Own\"" description: "\"A wildcard SSL certificate protects *.yourdomain.com — the main domain plus all its subdomains — without issuing a separate certificate for each one.\"" canonical: https://penasihathosting.com/en/hosting-wiki/wildcard-ssl type: wiki locale: en updated: 2026-09-29 author: Willya Randika --- # "Wildcard SSL: One Certificate for Every Subdomain You Own" ## Overview - **Summary:** "A wildcard SSL certificate protects *.yourdomain.com — the main domain plus all its subdomains — without issuing a separate certificate for each one." - **Author:** Willya Randika ([profile](/penulis/willya-randika)) ## Article ## What Is Wildcard SSL? A wildcard SSL certificate is a single certificate that covers your main domain and every subdomain under it, written as `*.yourdomain.com`. With one installation, `shop.yourdomain.com`, `blog.yourdomain.com`, and any subdomain you create tomorrow are all covered automatically. The difference from a standard single-domain certificate is scope. A single-domain certificate locks exactly one name. A wildcard locks a pattern: everything one level below your domain. 💡 Simple analogy: A single-domain certificate is a key for one specific room. A wildcard SSL is a master key for every room on the same floor — a room built tomorrow still fits, no re-keying needed. But remember: this master key does not work on other floors (other domains), and it does not automatically open rooms one floor further down (nested subdomains). ## How Wildcard SSL Works When you request a wildcard certificate, the Certificate Authority verifies that you control the domain through **DNS validation**: you add a specific TXT record. Because verification happens at the domain level, new subdomains never need to be re-verified — that is the whole practical point. Once installed, it behaves exactly like ordinary HTTPS. The browser checks that the name you are visiting matches the `*.yourdomain.com` pattern in the certificate, then the connection is encrypted. Visitors notice nothing different. One technical limit worth knowing: a wildcard covers **one level only**. `*.yourdomain.com` includes `app.yourdomain.com`, but not `cdn.app.yourdomain.com`. For nested subdomains you need an additional certificate or a multi-domain one. ## Why It Matters When Choosing Hosting Wildcard needs usually appear when your architecture branches out. A few concrete situations: * **You run many [subdomains](/en/hosting-wiki/subdomain)** for staging, client portals, or separate apps on one domain. One wildcard is far tidier than managing dozens of individual certificates. * **You host services for clients.** If you are a reseller or agency with subdomain-based tenants, a wildcard is literally the tool for the job. * **You work inside [cPanel](/en/cpanel-hosting)** or a similar control panel. At the shared-hosting level, commercial wildcard certificates are usually paid and issued manually, so check availability with your provider first. An important note for most readers: if your only motive is "all subdomains get free HTTPS", a wildcard is not necessarily the cheaper path. [Let's Encrypt](/en/hosting-wiki/lets-encrypt) issues free single-domain certificates with automatic renewal, and many panels now provision one per subdomain automatically. Let's Encrypt wildcards exist too, but only via DNS validation — meaning you need access to your domain's DNS zone. ## Common Mistakes and Practical Tips **Buying a wildcard for one or two subdomains.** For `www` plus a blog, a plain (or free Let's Encrypt) certificate is simpler and cheaper. Count your real subdomains first. **Assuming a second domain is included.** A wildcard belongs to one domain. Do not expect `otherdomain.com` to be covered — for several distinct domains, the right shape is a multi-domain (SAN) certificate. **Installing the wildcard while [mixed content](/en/hosting-wiki/http-vs-https) still warns.** A certificate secures the connection, not the page contents. Old URLs hardcoded as `http://` in your database will still trigger browser warnings. **Not tracking expiry.** Commercial wildcards have a validity period and must be renewed, just like any certificate. Set a reminder, or verify the installation and end date with an [SSL checker](/en/tools/ssl-checker). ## FAQs ### Does a wildcard cover the bare domain without www? Generally the pattern `*.yourdomain.com` does not include the bare `yourdomain.com`. Most issuers add the bare domain as a bonus SAN entry, but it is an issuer policy — make sure it is included at checkout. ### Can I use Let's Encrypt for a free wildcard? Yes. Let's Encrypt wildcards are free and widely supported, but issuance must go through the DNS-01 challenge — you need to be able to add a TXT record to your domain's DNS. Email or file validation will not work for wildcards. ### Wildcard or multi-domain — which is right? Wildcard: many subdomains under one domain. Multi-domain (SAN): several different domains in one certificate. Agency setups often need both, and some issuers sell combined packages. ### Does wildcard SSL affect site speed? No. The HTTPS handshake overhead is identical to a regular certificate. The real gain is operational: no per-subdomain certificate management. ## Bottom Line A wildcard SSL certificate is an investment in tidiness rather than a special grade of security: one issuance, one installation, every one-level subdomain covered. It makes sense when your subdomains are genuinely numerous and keep growing. For a site with a handful of subdomains, free per-subdomain certificates from Let's Encrypt usually do the job — choose based on your infrastructure shape, not because "wildcard" sounds more premium.