Skip to content
Hosting Operations8 min read

Wildcard SSL Certificates: 5 Options Compared [2026]

Compare Let's Encrypt, commercial CAs, and self-signed wildcard SSL certificates. Find the right option for your subdomains and budget.

Written by Abdul AbrorTechnical Hosting Support Engineer
a golden padlock sitting on top of a keyboard
On this page

TL;DR — Key takeaways

  • Let's Encrypt wildcard certificates are free but require DNS-01 challenge automation and renew every 90 days
  • Commercial wildcard SSL certificates from DigiCert or Sectigo cost $200-400/year but offer extended validation and longer validity periods
  • Self-signed wildcards work for internal testing but browsers will show security warnings in production
  • cPanel AutoSSL cannot issue wildcards automatically; you must use manual DNS validation or ACME DNS plugins
  • A single wildcard certificate covers *.example.com but not example.com itself or nested subdomains like *.api.example.com

A wildcard SSL certificate secures all first-level subdomains under a single domain with one certificate. Instead of buying and managing separate certificates for www, mail, shop, and api, you install *.example.com once.

The certificate market offers three main paths: free automated certificates from Let's Encrypt, commercial certificates from established CAs like DigiCert and Sectigo, and self-signed certificates for internal use. Each has different costs, validation requirements, and operational overhead.

I've set up wildcard certificates across shared hosting, VPS environments, and dedicated servers. The right choice depends on your DNS automation capability, budget, and whether you need extended validation for customer trust. Let's compare the options.

Let's Encrypt Wildcard Certificates: Free But DNS-Dependent

Let's Encrypt wildcard certificates are free and trusted by all major browsers. The catch is the DNS-01 challenge requirement. You must prove domain ownership by creating a TXT record at _acme-challenge.yourdomain.com, which means your DNS provider needs either API access or manual intervention every 90 days.

Most ACME clients like certbot support DNS plugins for common providers (Cloudflare, Route53, Google Cloud DNS). The plugin adds the TXT record automatically during issuance and renewal. Without API access, you're stuck manually pasting DNS records three to four times per year.

The 90-day validity is shorter than commercial certificates, but automated renewal handles this. Set your renewal cron job to run at least 30 days before expiration. In support tickets I handled, the usual culprit was a broken DNS plugin credential or a deleted API token that stopped renewals cold.

  • Free, unlimited certificates
  • Requires DNS-01 validation (TXT record automation)
  • 90-day validity with automated renewal
  • No extended validation or organization fields
  • Works with certbot, acme.sh, and other ACME clients
  • DNS propagation delays can block initial issuance (wait 5-10 minutes after adding TXT record)

Commercial Wildcard SSL: Paid Certificates From Established CAs

Commercial wildcard certificates from vendors like DigiCert, Sectigo, Thawte, and GeoTrust cost $200 to $400 per year for domain validation (DV) and $600+ for organization validation (OV). You get 1-year validity (some CAs still offer 2-year purchase with annual reissuance), dedicated support, and a warranty against mis-issuance.

The validation process is lighter than Let's Encrypt's DNS-01 automation. Most commercial CAs accept email validation ([email protected]), DNS CNAME, or HTTP file upload. You prove ownership once per year instead of maintaining ongoing DNS API access.

Extended validation wildcards are rare and expensive. If your users check the certificate details or your compliance team requires OV, commercial makes sense. For most sites, the browser shows the same padlock either way.

  • Domain validation: $200-400/year
  • Organization validation: $600+/year
  • 1-year validity (up to 398 days per CA/Browser Forum baseline)
  • Email, DNS, or HTTP validation methods
  • Includes warranty ($10k-$1.75M depending on CA and validation level)
  • Dedicated support and reissuance if private key is compromised

Self-Signed Wildcard Certificates: Internal Use Only

Self-signed wildcard certificates cost nothing and take five minutes to generate with openssl. They're perfect for staging environments, internal APIs, and local development where you control the client trust store.

Browsers and API clients will throw certificate warnings because there's no trusted CA in the chain. You can add your self-signed CA to system trust stores on internal machines, but you'll never get the green padlock in a customer's browser.

Generate a self-signed wildcard with: openssl req -x509 -newkey rsa:4096 -keyout wildcard.key -out wildcard.crt -days 365 -nodes -subj '/CN=*.example.com'. Add subjectAltName entries in an openssl.cnf file if you need the apex domain included.

  • Free and instant generation
  • No CA validation or renewal required
  • Browsers show 'Not Secure' warnings in production
  • Suitable for development, staging, and internal networks
  • Must distribute the CA certificate to client trust stores manually

Wildcard SSL in cPanel: AutoSSL Limitations and Manual DNS Setup

cPanel AutoSSL does not issue wildcard certificates automatically. It uses HTTP-01 validation, which cannot prove ownership of *.example.com because there's no single web root for all possible subdomains.

To get a wildcard in cPanel, use the SSL/TLS interface to generate a CSR, then complete DNS-01 validation through Let's Encrypt manually or install a purchased commercial certificate. Some hosting providers offer ACME DNS plugins through the command line (certbot with the appropriate DNS plugin), but that's outside the standard cPanel UI.

Once you have the wildcard certificate file and private key, paste them into SSL/TLS → Install an SSL Website. The certificate applies to the domain and all first-level subdomains defined in your DNS zone.

    When to Choose Each Option: Decision Matrix

    Choose Let's Encrypt if you have DNS API access and want zero cost. It's the default for most modern hosting setups. Cloudflare users get seamless integration, and AWS Route53 works cleanly with certbot-dns-route53.

    Pick a commercial wildcard if you lack DNS automation, need organization validation for compliance, or want annual renewal instead of 90-day cycles. The cost is justified when your DNS provider has no API or when procurement prefers a single yearly invoice.

    Self-signed certificates are for internal infrastructure only. Use them freely in development and staging, but never in production where external users connect.

    • Let's Encrypt: Free, automated, DNS API required, 90-day renewal, DV only
    • Commercial: $200-400/year, email/DNS/HTTP validation, 1-year term, OV available
    • Self-signed: Free, instant, no validation, browser warnings, internal use only

    Common Wildcard SSL Troubleshooting

    If DNS-01 validation fails, check TXT record propagation with dig _acme-challenge.example.com TXT. Some DNS providers take 5-10 minutes to propagate; others are instant. Wait for the record to appear in public DNS before retrying.

    A wildcard cert installed but subdomains still show certificate errors? The web server might not be configured to serve the wildcard for virtual hosts. In Apache, check that the SSLCertificateFile directive points to the wildcard cert in each subdomain's VirtualHost block. In Nginx, verify the ssl_certificate path in the server block.

    Remember that *.example.com does not cover example.com itself. If your apex domain needs HTTPS, install a second certificate or use a multi-domain SAN that includes both example.com and *.example.com.

    • Verify DNS TXT record propagation before assuming validation failed
    • Check web server virtual host configuration to ensure the wildcard cert is loaded for all subdomains
    • Install a separate certificate for the apex domain if the wildcard doesn't cover it
    • Test certificate coverage with: openssl s_client -connect subdomain.example.com:443 -servername subdomain.example.com
    • Check certificate SAN field to confirm *.example.com is listed

    Renewal and Automation Strategy

    Automate Let's Encrypt renewals with a cron job that runs certbot renew twice daily. The client only renews certificates expiring within 30 days, so frequent checks don't waste resources. Pair this with a post-renewal hook that reloads your web server: certbot renew --deploy-hook 'systemctl reload nginx'.

    For commercial certificates, set a calendar reminder 45 days before expiration. Reissue through your CA's portal, complete validation, and install the new certificate. Some CAs email renewal reminders, but I've seen those emails land in spam or get ignored.

    Store your DNS API credentials and CSRs in a password manager or encrypted vault. You'll need them again in 90 days or a year. Lost credentials mean manual DNS validation, and lost private keys mean full reissuance.

      Quick troubleshooting checklist

      • Verify your DNS provider supports TXT record automation or API access
      • Choose between free (Let's Encrypt) and paid (commercial CA) based on validation level needed
      • Test DNS propagation with dig _acme-challenge.yourdomain.com TXT before requesting the certificate
      • Configure your web server to serve both the wildcard cert and a separate cert for the apex domain if needed
      • Set up automated renewal 30 days before expiration
      • Document your DNS-01 validation credentials in a secure location
      • Test the installed certificate across multiple subdomains before going live

      FAQ

      Does a wildcard SSL certificate cover the root domain and all subdomains?

      A wildcard certificate for *.example.com covers first-level subdomains like www.example.com, mail.example.com, and shop.example.com, but it does not cover the root domain example.com itself or nested subdomains like *.api.example.com. You need a separate certificate for the apex domain or a multi-domain SAN certificate to cover both.

      Can I get a free wildcard SSL certificate from Let's Encrypt?

      Yes, Let's Encrypt offers free wildcard certificates, but you must use the DNS-01 challenge method which requires adding a TXT record to your domain's DNS zone. HTTP-01 validation does not work for wildcards. The certificate is valid for 90 days and must be renewed automatically using an ACME client like certbot with DNS plugin support.

      What is the difference between a wildcard SSL and a multi-domain SAN certificate?

      A wildcard certificate covers unlimited subdomains at one level (*.example.com) but only for a single domain. A multi-domain SAN certificate covers a specific list of fully qualified domain names across different domains (example.com, www.example.com, shop.anotherdomain.com) but does not use wildcards. Choose wildcards when you have many subdomains on one domain; choose SAN for a few specific domains.