Skip to main content
HostingSeller
Shop plans

Failure Modes

Hosting with free SSL — The failure your client's customers see before your client does

Nobody notices a certificate that works; everybody notices a browser warning, and on a book of forty accounts the odds of one lapsing are not a matter of opinion.

Straight answer first

Free certificates issued and reissued automatically are the only sane arrangement once you carry more than a handful of client sites, because a lapse is the most publicly visible failure in this trade and manual renewal across forty accounts will eventually miss one.

The rest of this page is the operational detail: the four situations where automatic issue genuinely does not fire, what your client's visitors see when it happens, when a paid wildcard or EV certificate earns its place on your invoice, and the check that should be in your monthly routine.

Written by the Hosting Seller staff · Checked 24 August 2026

Free

Migration when clients move in

24/7

Cover for certificate emergencies

Daily

Backups on client accounts

$0

Charged for basic certificates

Since automated certificate authorities arrived, a charge for basic SSL has been margin and nothing else — machines do the issuing, the fitting and the renewing without a human going near them. For a reseller that is not a pricing argument so much as an operational one: the value is not that the certificate is free, it is that nobody has to remember it.

Free SSL is issued on every plan, on every site you host, and reissues before it lapses. The paid shelf is deliberately short: Wildcard SSL at $169.99/yr covering every subdomain, and EV SSL at $379.99/yr carrying a checked company name. Those exist for the two things a free DV certificate genuinely cannot do.

What your client's visitors actually see

Not a subtle indicator. A full-page interstitial in every modern browser saying the connection is not private, with the site's name in it, and a button the visitor has to deliberately override. For a brochure site that is embarrassing. For a checkout it is the end of the session, and for a login form it is a support call from every user at once.

The client usually finds out from a customer rather than from you, which is the part that damages the relationship. They will ask, reasonably, what exactly they are paying you for — and the honest answer, if you were renewing certificates by hand, is nothing that a machine could not have done better.

So this is a failure to design out rather than to respond to quickly. Certificates that issue the moment a site is added to an account and renew themselves from then on remove the failure class entirely, which is worth considerably more than the fifty or a hundred dollars a year that the certificates themselves would have cost.

The four times automatic issue does not fire

The domain is not pointing here yet. Validation needs the name to resolve to the account, so a site staged on a temporary URL with the domain still at the old host will not get a certificate for that domain until DNS changes. Plan the order of operations rather than discovering this at go-live.

A CAA record blocks it. Some clients arrive with a CAA record from a previous supplier restricting which authority may issue. It is invisible until you look, and it is the single most common reason a certificate silently fails to appear on a migrated site.

The site is behind a proxy the client controls. If a client has put a third-party proxy or CDN in front, the validation path may never reach the account. Ask at onboarding whether anything sits in front of the site — clients rarely volunteer it because they do not think of it as hosting.

A subdomain nobody told you about. Certificates cover the domains on the account, so a new subdomain created outside your process gets no certificate. This is one of several reasons to be deliberate about who in a client's organisation can add hostnames.

When a paid certificate earns its line

Wildcard, at $169.99/yr, when the client's application spins up subdomains. A multi-tenant app that gives every customer their own hostname cannot practically be served by per-name certificates, and one wildcard covering *.theirdomain solves it in a single line. It carries a $10,000 relying-party warranty and is usually issued the same day, and our team fits it at no extra charge.

EV, at $379.99/yr, when the client's own customers need to see a verified company name in the certificate — typically at a login box or a checkout where the client is arguing for trust against larger competitors. It carries a $1,500,000 warranty and takes one to three days to issue because a human checks the company exists.

For everything else, do not sell one. The encryption in a free DV certificate is identical; what money buys is wildcard cover, organisation validation or a warranty — procurement features rather than a stronger padlock. A reseller who bills for basic certificates on top of hosting that already includes them is charging for a junk fee, and the client will eventually find out.

The check that belongs in your monthly routine

Once a month, list every hostname you are responsible for and check the certificate expiry on each. Twenty seconds per site by hand, or a single script if you would rather. This is not a substitute for automation — it is the audit that catches the four cases above, all of which are silent failures rather than errors.

Add one more check while you are there: that HTTP forwards to HTTPS. It is configured by default, and it is exactly the sort of thing that gets changed by a client's plugin, a caching rule or a well-meaning developer. A site with a valid certificate that still serves on plain HTTP is a mixed-content problem waiting for a payment page.

Record the result. When a client asks at renewal what they got for their money, 'twelve monthly certificate audits, no lapses' is a line in an annual summary rather than a claim. Keeping the record as you go costs nothing and makes the invoice unarguable.

A padlock on a laptop screen standing in for a free SSL certificate

Included, on every site you create

Free SSL applies to every site on every account you host, not just the domain on your own invoice. On a reseller plan that means every client site you create is covered from the moment its name points here.

The paid shelf is deliberately short — wildcard and EV only — because a paid DV certificate alongside free SSL on every plan is a product that argues with itself, and we would rather not sell it to you to resell.

  • Certificates issued and reissued automatically
  • Every site on every client account covered
  • Wildcard at $169.99/yr for subdomain-heavy apps
  • EV at $379.99/yr where a company name must show

Why Hosting Seller

On every plan, as standard

A failure class removed

Automatic issue and reissue takes the most publicly visible reseller failure out of the category of things that can happen.

Every client site, not just yours

Free SSL covers every site on every account you create, so coverage does not depend on remembering to ask.

Wildcard for multi-tenant clients

$169.99/yr covers *.theirdomain with a $10,000 warranty, usually issued the same day and fitted for you.

EV where trust is the argument

$379.99/yr puts a checked company name in the certificate, with a $1,500,000 relying-party warranty behind it.

No junk fee to pass on

Basic certificates cost nothing here, so there is no line you have to justify to a client who has read about Let's Encrypt.

Fitting done for you

Paid certificates are installed by our team at no extra charge, which keeps a $169.99 sale from costing you an afternoon.

First Steps

From choosing to live

  1. 1

    Check for CAA records at migration

    A restriction left behind by a previous supplier is the most common silent cause of a certificate that never appears.

  2. 2

    Ask what sits in front of the site

    Clients rarely mention a proxy or CDN because they do not think of it as hosting, and it can block the validation path.

  3. 3

    Sequence DNS before go-live

    Validation needs the name resolving to the account, so plan the order of operations rather than discovering it on launch day.

  4. 4

    Audit expiries monthly and record it

    A list of every hostname and its expiry catches the silent failures, and the record answers the renewal question later.

In the Box

Packed with every plan

  • Free SSL confirmed active on every client site you host
  • CAA records checked on every domain you migrate in
  • Any client-side proxy or CDN identified at onboarding
  • HTTP to HTTPS forwarding verified per site
  • A monthly expiry audit across every hostname you carry
  • The audit result recorded for the annual client summary
  • Wildcard considered for any multi-tenant client application
  • EV considered only where a verified company name matters
  • No basic certificate billed to a client as an extra
  • Who may add hostnames on a client account decided in writing

Across the Counter

Things people ask us all the time

Should I charge clients for SSL at all?

Not for basic certificates. They are included on every plan and issue automatically, and a client who searches the subject will find that out within a minute. If you want the revenue, price it into the retainer as certificate management — the monthly audit, the CAA checks, the forwarding verification — which is real work you actually do. Billing for the certificate itself is the junk fee this market is known for.

A migrated client site has no certificate. Where do I look first?

CAA records, then DNS. A CAA record left over from a previous supplier restricting which authority may issue is the most common cause and is invisible unless you check. After that, confirm the name actually resolves to the account — validation cannot complete for a domain still pointing at the old host, which is why the order of operations at go-live matters.

When is a wildcard certificate worth reselling?

When the client's application creates subdomains — a multi-tenant product giving each customer their own hostname, or a platform with a per-client subdomain. One certificate at $169.99/yr covers *.theirdomain, carries a $10,000 relying-party warranty, is usually issued the same day and is fitted by our team at no extra charge. For a fixed handful of subdomains, individual free certificates remain the better answer.

Does an EV certificate actually help a client convert?

It gives them something specific to point at: a certificate carrying their checked company name, backed by a $1,500,000 relying-party warranty, issued after a human verified the company exists. Whether that moves a conversion rate is the client's judgement to make about their own market. Sell it where the client is arguing for trust against larger competitors at a login or a checkout, and do not sell it anywhere else.

What do I do if a client's certificate lapses despite everything?

Fix it before you explain it — the certificate reissues quickly once whatever blocked it is cleared. Then tell the client what happened and what has changed so it cannot recur, in writing, the same day. A lapse handled openly within an hour is survivable; a lapse the client hears about from a customer, and then has to chase you about, is the one that loses the account.

Read next

  • API Backend Hosting

    The client whose product is an API rather than a website, and the certificate questions that come with it.

  • Hosting for High-Traffic Blogs

    The publisher account whose good day arrives as bandwidth, and what to verify before it does.

  • SSL Certificates

    Free certificates on every client site, with wildcard and EV for the two cases a free one cannot cover.

  • VPS Hosting

    KVM servers with full root and DDoS filtering, for the client who has genuinely outgrown a shared allotment.

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Take the lapse off the table.

Free certificates on every site of every client account you create, with wildcard and EV on the shelf for the two cases that need them.

See SSL Certificates plans