Skip to main content
HostingSeller
Shop plans

White-Label Brief

Hosting for wildcard SSL — Your own brand needs the subdomains before your clients do

Written for anybody putting a hosting brand on the counter, where cp, mail and billing all have to open without a browser warning attached to somebody else's name.

Straight answer first

Use the free per-subdomain certificates for the fixed handful you create by hand, and buy a Wildcard SSL certificate once subdomains start appearing without you — one certificate written as *.yourdomain covers every first-level subdomain the moment it exists, including the ones you have not thought of yet.

For a reseller the first subdomains that matter are your own. A white-label arrangement puts a client in front of addresses on your brand, and every one of them has to open cleanly, because a certificate warning on cp.yourbrand is the single fastest way to lose the impression you have been building.

Written by the Hosting Seller staff · Checked 24 August 2026

Free

Migration into the account

24/7

Cover at any hour

Daily

Backups across every account

$0

To open a new account

A wildcard certificate covers *.yourdomain across one level: every first-level subdomain you care to create, under one certificate, with anything deeper needing its own arrangement. That is the whole technical story, and it takes one sentence.

The interesting part is operational. Which subdomains exist, who creates them, and whether they appear faster than a person can issue certificates for them. Those three answers decide whether you need a wildcard or merely the free automation.

The subdomains on your own brand

Before a single client subdomain exists, a hosting brand has its own set: the control-panel address clients log into, the webmail address, the billing address, and the nameservers you publish. Each of those is a first-level subdomain of your domain and each is somewhere a client will end up.

Private nameservers are the case people forget. They are host records rather than websites, so they do not need a certificate themselves — but the panel and webmail addresses beside them very much do, and a warning on either undermines the whole arrangement.

One certificate written as *.yourdomain covers the lot, including the ones you add later when you decide the status page or the knowledge base deserves its own address. That is the argument for a wildcard on a brand domain even when the client count is small.

Where the free route is genuinely sufficient

Free SSL is issued automatically on every plan, per hostname, and reissues itself before it lapses. For a fixed handful of subdomains that you create deliberately, that is the correct answer and paying for anything else is waste.

The free route also handles client sites well. Every client account gets its own certificate on its own domain and its own www, without anybody diarising a renewal, which is precisely the sort of recurring per-site task you cannot afford across a fleet.

The point at which it stops being sufficient is not a number of subdomains; it is whether they are created by a person or by software. Anything issued by hand can be automated. Anything that appears on its own cannot wait for you.

Tenant applications that mint subdomains on their own

Client portals, multi-tenant applications and anything that gives each customer their own address create subdomains at signup — at three in the morning, without asking. Issuing certificates by hand for that is automation debt with a due date attached.

A wildcard covers whatever appears, the moment it appears, which turns a recurring operational problem into a one-off purchase. On our shelf the Wildcard SSL certificate is issued for both the bare domain and *.yourdomain, is usually issued the same day, carries a relying-party warranty, and our team fits it at no extra charge.

Remember the depth limit before you promise anything. A wildcard covers one level, so app.yourdomain is covered and tenant.app.yourdomain is not. Multi-level structures need a second certificate or a flatter naming scheme, and flattening the names is nearly always the cheaper answer.

Fitting it, and where it can live

One certificate can be installed on as many servers as you need and reissued as often as you like, which matters when the panel, the mail service and a separate application server all answer on the same brand domain.

Decide who holds the private key and where it is recorded. On a small team that document is the difference between a routine reissue and an afternoon of reconstruction, and it is exactly the sort of thing nobody writes down until the second time.

Diary the expiry rather than trusting memory. Free certificates renew themselves; a purchased wildcard is an annual product and its lapse would take out every branded address at once, which is the most visible failure available to a white-label brand.

A padlock on a laptop screen standing in for a free SSL certificate

Why we sell only two paid certificates

Every plan already includes free automatic SSL, so advertising a paid single-domain certificate alongside it would have the catalogue arguing with itself. The two we do stock sell on the things the free route genuinely cannot do: unlimited first-level subdomains from one certificate, and a verified company identity.

That is also why this page tells you to use the free route wherever it fits. A certificate sold to somebody who did not need one is a refund conversation waiting to happen.

  • Free automatic SSL on every plan and every client site
  • One wildcard covering *.yourdomain across one level
  • Issued for the bare domain as well as the subdomains
  • Installed on as many servers as you need

Why Hosting Seller

On every plan, as standard

Your brand opens cleanly

Panel, webmail and billing addresses on your own domain, all covered by one certificate, with no warning anywhere a client will land.

Coverage for what appears on its own

A wildcard covers subdomains created by software at three in the morning, which no manual issuing process can keep up with.

Free where free is right

Automatic per-hostname certificates on every plan handle fixed subdomains and every client site without a diary entry.

The bare domain included

Ours are issued for yourdomain as well as *.yourdomain, which is worth confirming wherever you buy one.

Fitted for you

Our team installs it at no extra charge and it can be reissued as often as you need across as many servers as you run.

Usually issued the same day

Domain validation rather than an organisation check, so the certificate is generally available within the working day.

First Steps

From choosing to live

  1. 1

    List the subdomains on your own brand first

    Panel, webmail, billing, status, knowledge base. Those are the addresses a client meets before any of their own exist, and they are the ones a warning would damage most.

  2. 2

    Ask whether subdomains are created by a person or by software

    Anything issued by hand can use the free automation. Anything that appears on its own needs coverage that already exists when it does.

  3. 3

    Flatten the naming before buying a second certificate

    A wildcard covers one level. Renaming tenant.app.yourdomain to tenant-app.yourdomain is usually cheaper than a second certificate and simpler to reason about.

In the Box

Packed with every plan

  • Free SSL issued automatically on every plan and client site
  • Certificates reissued before they lapse without a diary entry
  • A wildcard covering *.yourdomain across one level
  • Issued for the bare domain as well as the subdomains
  • Installed on as many servers as your arrangement needs
  • Reissued as often as you need at no extra charge
  • Fitted by our team rather than left to you
  • Usually issued the same day on domain validation
  • Private nameservers published under your own brand
  • A note recording who holds the key and where it lives

Across the Counter

Things people ask us all the time

Which subdomains does a white-label hosting brand actually need covered?

Its own, before any client's. The control-panel address clients log into, webmail, billing, and anything else on your domain that a customer will meet. Private nameservers are host records and need no certificate themselves, but the panel and webmail beside them do — and a warning there undoes the impression the whole arrangement exists to create.

When is free per-subdomain SSL enough?

Whenever the subdomains are created deliberately by a person. Free certificates are issued automatically per hostname and reissue themselves, which covers a fixed handful and every client site without a diary entry. The threshold is not a count — it is whether something other than you is creating the names.

Does a wildcard cover subdomains of subdomains?

No. It covers one level, so app.yourdomain is included and tenant.app.yourdomain is not. Where a multi-level structure has appeared, flattening the naming scheme is usually cheaper and simpler than buying a second certificate — and it is easier for whoever inherits the arrangement to reason about.

What happens if a purchased wildcard lapses?

Every branded address fails at once, which is the most visible failure available to a white-label brand. Free certificates renew themselves; a purchased wildcard is an annual product, so diary the expiry and record who holds the key. That note is the difference between a routine reissue and an afternoon of reconstruction.

Read next

  • Hosting With a Free Domain

    The domain-plus-hosting arithmetic, read from the side of somebody buying names for clients.

  • Cheap Dedicated Servers

    Bare metal priced against what it costs to administer rather than against a spec sheet.

  • SSL Certificates

    SSL free on every plan, with wildcard and EV on the shelf when a client genuinely needs one.

  • Web Hosting

    cPanel hosting on NVMe with SSL, migration and the first year of the domain included.

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Put every branded address behind one certificate.

Free SSL on every client site, a wildcard for the subdomains that appear on their own, and our team fitting it for you.

See SSL Certificates plans