4 min read Sep 26, 2026

How to Get Free SSL with AutoSSL and Force HTTPS in cPanel

Check and issue free SSL certificates with AutoSSL in cPanel, turn on Force HTTPS for each domain, install a paid certificate, and fix the most common SSL errors.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

SSL (TLS) encrypts traffic between visitors and your website, shows the padlock in the browser and is required by Google, payment gateways and modern browsers. cPanel Hosting servers include AutoSSL, which issues free domain-validated certificates for your domains and renews them automatically before they expire. You normally do not need to do anything except make sure your domain points to the server and then turn on HTTPS redirection.

How AutoSSL works

  • The server runs AutoSSL regularly and requests certificates for every domain and subdomain in your account, including www. and service names such as mail., cpanel. and webmail. when they point to the server.
  • To prove you control the domain, the certificate authority checks a temporary file on your website or a DNS record. This only succeeds when the domain’s DNS points to your cPanel server.
  • Certificates are renewed automatically, well before they expire.

Check your SSL status

  1. Log in to your FimuroHost client area at https://app.fimurohost.com.
  2. Go to Services and select your cPanel Hosting plan.
  3. Click Login to cPanel. cPanel opens in a new tab, already signed in.
  4. In the Security section, click SSL/TLS Status.
  5. Each domain shows an icon and status: a green padlock with AutoSSL Domain Validated means the certificate is active. A red or unlocked icon means no valid certificate yet.
  6. If your domain has only recently been pointed to FimuroHost, click Run AutoSSL. It can take several minutes; reload the page afterwards.

If a domain still fails, the status or the log link on the page explains why. The most common reasons are listed below.

Turn on Force HTTPS

Once a certificate is active, make sure everyone uses the secure address:

  1. Go to Domains » Domains.
  2. Switch Force HTTPS Redirect to On for each domain with a valid certificate.
  3. Open http://yourdomain.com in a private window; it should jump to https://.

For WordPress, also set Settings » General » WordPress Address and Site Address to https://. If some images still load over http://, you will see a “Not secure” or mixed-content warning; update those links, or use a search-and-replace plugin to change http://yourdomain.com to https://yourdomain.com in the database.

Installing a paid or third-party certificate

If you bought an OV or EV certificate elsewhere:

  1. Go to Security » SSL/TLS and under Certificate Signing Requests (CSR) generate a CSR for your domain. Give the CSR to your certificate provider.
  2. When you receive the certificate (.crt) and CA bundle, go to SSL/TLS » Manage SSL sites.
  3. Choose the domain, paste the certificate into Certificate: (CRT), click Autofill by Certificate (this finds the private key created with the CSR), check that the CA bundle is filled in, and click Install Certificate.

AutoSSL does not replace a valid paid certificate. When the paid certificate expires, renew it and install the new one the same way.

Why AutoSSL fails, and fixes

CauseFix
Domain still points to the old host or wrong IPSet the nameservers from your welcome email, or point the A records (for the domain and www) to your server IP. Wait for DNS to update, then run AutoSSL.
Cloudflare proxy (orange cloud) is onTemporarily switch the records to “DNS only”, run AutoSSL, then turn the proxy back on and set Cloudflare SSL mode to Full (strict).
.htaccess redirects or blocks the validation requestRemove custom redirect or security rules temporarily, run AutoSSL, then restore them.
A CAA DNS record allows only a different certificate authorityRemove or update the CAA record in Zone Editor.
www or mail subdomain has no DNS recordAdd the missing A or CNAME record so that name can be validated too.

Common problems

  • “Too many redirects” after turning on Force HTTPS: another HTTPS redirect (in .htaccess, a plugin or Cloudflare set to Flexible) is fighting with it. Keep one method only, and use Full (strict) in Cloudflare.
  • Padlock shows but a warning appears on some pages: mixed content; see the WordPress note above.
  • Email apps warn about the certificate: check that mail.yourdomain.com is covered in SSL/TLS Status, or use the server hostname in your mail settings.

Need help?

If anything in this guide does not match what you see, or you get stuck, open a support ticket (choose the Support department) or message us on WhatsApp at 01818160926. Tell us your domain name and what you have tried so far, and never send your password in a ticket or chat.

FimuroHost Team

Written by

FimuroHost Team

Technical Writer