The "Not Secure" warning that scares customers away. Without SSL, browsers flag your site "Not Secure" — costing you sales, trust, and search ranking. Every plan includes SHA-2, 2048-bit encryption, and issuance in minutes.
Google made HTTPS a confirmed ranking signal back in 2014 — and it hasn't stopped mattering since.
Three things, all at once, the moment it's installed.
Data between your visitor and your site is scrambled with SHA-2 hashing and up to 256-bit encryption — the same standard trusted by banks and Fortune 500 companies.
It proves you are who you claim to be, earning the trust signals visitors recognize — HTTPS in the address bar and a browser security indicator.
Google favors secure sites. Installing SSL gives you a real SEO advantage over unencrypted competitors.
Not confident installing and maintaining it yourself? See our Managed SSL Service instead.
The essential lock for a single site. Instant HTTPS activation.
One certificate, five sites — pure efficiency for a growing portfolio.
Protects unlimited subdomains under one domain — the master key.
The highest trust signal — verified legal business identity for one site.
Extended validation trust, applied across up to five high-value sites.
Pricing excludes applicable taxes and ICANN fees.
Free certificates use the same core encryption we do — the real differences show up in how long they last, what they verify, and what happens when something goes wrong.
| Spec | Free SSL | Our SSL |
|---|---|---|
| Signature algorithm | SHA-2 (SHA-256) | SHA-2 (SHA-256) |
| Root key size | 2048-bit RSA | 2048-bit RSA |
| Validity period | Typically 90 days, renews automatically | Up to 1 year |
| Validation options | Domain only | Domain, or Extended with verified business identity |
| Trust site seal | not included | included |
| Support if setup goes wrong | Community forums | Dedicated support, 24/7 |
| Reissuance | Manual, self-managed | Free, unlimited, we handle it |
What you're actually buying, and how to pick the right level.
| Type | Validation check | Ideal for | Trust signal |
|---|---|---|---|
| Domain Validated (DV) | Verifies domain ownership only, via email or file | Personal sites, blogs, basic business sites | HTTPS protocol, no "Not Secure" warning |
| Extended Validation (EV) | Rigorous vetting of your legal, operational, and physical business existence | E-commerce, financial services, major brands | Verified legal company name in browser certificate details |
If you're used to looking for a padlock, here's what changed — and why it doesn't mean SSL matters any less.
Why the padlock disappeared: Research showed most users misread the padlock as "this site is entirely safe," when it only ever meant the connection was encrypted. Scam sites could — and did — install a certificate and display it too.
HTTPS became the default: Today over 95% of web traffic is encrypted. A padlock highlighting the exception made sense when secure sites were rare — now that they're the norm, it stopped being a useful signal.
What you'll see instead: Chrome (117 and later) replaced it with a neutral "tune" icon that opens connection details on click — without implying the whole site is trustworthy. Your connection is still just as encrypted either way.
A digital passport for your website that creates a secure, encrypted connection between your server and a visitor's browser. It's what turns http:// into https:// in the address bar.
It protects sensitive data like passwords and credit card numbers, improves your Google search ranking, and builds visitor confidence by showing your site is secure.
Check the address bar for https://. That's the one universal signal that the connection is encrypted — regardless of which icon (or no icon) your browser shows next to it.
Yes. Even without payments, SSL protects user logins and contact forms, and it's a ranking factor for Google regardless of what your site does.
Most standard certificates are valid for 13 months (one year plus a grace period). You'll need to renew before it expires to keep your site secure.
Visitors see a "Your connection is not private" warning, which will scare people away and hurt your credibility — and your site gets served over unencrypted HTTP again.
DV verifies just the domain name and issues fastest. EV verifies the domain and your legal business identity, for the highest trust signal. Wildcard secures one domain plus unlimited subdomains under it.
Yes — all single-site certificates automatically secure both yourdomain.com and www.yourdomain.com at no extra cost.
Yes. Google uses SSL as a confirmed ranking signal. Websites using HTTPS get a slight ranking boost compared to non-secure HTTP sites — and it prevents search engines from penalizing your site or showing visitors a harsh "Not Secure" browser warning. Here's exactly how it helps: