Back to articles

How to enable free SSL in cPanel

September 2, 2026
cPanel

The SSL certificate is what makes the browser show the padlock and the address start with https://. Without it, Chrome marks the site as "Not secure" right next to the address โ€” and Google uses HTTPS as a ranking signal. At RedHosting the certificate is free on every hosting plan.

1. Most of the time it's already active

The hosting issues the certificate on its own, through AutoSSL, as soon as the domain starts pointing to the server. Before anything else, check:

  • Log in to cPanel and, under Security, click SSL/TLS Status.
  • The list shows each domain and subdomain on the account. A green padlock means the certificate is issued and valid.

If everything is green, skip to step 3.

2. Issuing the certificate manually

If any domain shows up without a certificate:

  • On the same SSL/TLS Status screen, check the box for the missing domains.
  • Click Run AutoSSL.
  • Wait a few minutes and reload the page.
โš ๏ธIf AutoSSL fails: The reason is almost always the same: the domain doesn't point to the hosting yet. The certificate authority needs to reach your site on the server to prove the domain is yours. Finish pointing the domain first and run it again.

3. Forcing the site to open over HTTPS

An issued certificate doesn't redirect by itself: the site keeps opening over http:// for anyone who types it that way. cPanel fixes this with one toggle:

  • Under Domains, click Domains.
  • Turn on the Force HTTPS Redirect toggle for the domain.

If you'd rather do it in .htaccess, at the top of the file in public_html:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
๐Ÿ’กTip: Use the cPanel toggle or the .htaccess rule, never both. Together they create a redirect loop and the browser complains it "redirected you too many times".

4. When the padlock stays broken

The certificate is valid, but the browser shows the padlock with a warning. That's mixed content: the page opened over HTTPS and is loading some image, CSS or script over HTTP.

To find the culprit, open the page, press F12 and check the Console tab โ€” the browser lists every insecure resource.

On a WordPress site, the fix is usually:

  • Under Settings โ†’ General, change the WordPress Address and Site Address to https://.
  • Run a search-and-replace plugin swapping http://yourdomain for https://yourdomain in the database. Old addresses stay stored in posts and don't change by themselves.

On a hand-built site, search for http:// in the HTML and CSS and replace it with a relative path โ€” /images/photo.png instead of the full address.

5. Renewal

AutoSSL renews on its own before expiry, with nothing for you to do. Renewal only fails if the domain stops pointing to the hosting โ€” in that case cPanel warns you by email.

6. After SSL

  • Update the site address in Google Search Console to the https:// version.
  • Check internal links and the sitemap, which may still use http://.
  • If you have email on the domain, the certificate also covers mail.yourdomain.com โ€” it's worth reconfiguring your phone to use SSL/TLS.

Need help?

Open a ticket at financeiro.redhosting.com.br or contact support on WhatsApp at +55 11 98833-3902.

Frequently asked questions

Is RedHosting's SSL paid? +
No. The certificate is free on every hosting plan and issued automatically by AutoSSL.
AutoSSL failed. What should I do? +
The reason is almost always that the domain doesn't point to the hosting yet: the certificate authority needs to reach the site on the server to prove the domain is yours. Finish pointing it and run AutoSSL again.
The certificate is valid but the padlock is still broken. Why? +
It's mixed content: the page opened over HTTPS and loads some image, CSS or script over HTTP. Press F12 and check the Console tab, which lists every insecure resource.
Do I need to renew the certificate every year? +
No. AutoSSL renews on its own before expiry. Renewal only fails if the domain stops pointing to the hosting, and in that case cPanel warns you by email.
The site says it redirected too many times after I enabled HTTPS. +
You probably enabled the redirect with the cPanel toggle and also with an .htaccess rule. Use one of them, never both.