Free SSL Certificate: 5 Trusted Options and How to Install One

Short answer

A free SSL certificate encrypts your site with HTTPS at no cost. Let's Encrypt is the standard: browser-trusted, 90-day validity, renewed automatically with Certbot. If your DNS is on Cloudflare, Universal SSL is one click. Free certificates are domain-validated (DV), which is all most sites need.

Updated · 5 tools compared

Cost
0 USD
Validity per certificate
90 days (auto-renewed)
Time to install
< 5 minutes with Certbot

01 — Ranking

The 5 best options, ranked

  1. Let's Encrypt

    letsencrypt.org

    4.9

    Non-profit certificate authority that issues free, automated DV certificates through ACME.

    Best for
    Any server you control (Nginx, Apache, Node), using Certbot, acme.sh or a web server with built-in ACME.
    Free plan & limits
    Unlimited free DV certificates with no account. Each certificate is valid for 90 days, and Let's Encrypt plans to shorten this further. Wildcards are available through the DNS-01 challenge. Rate limits apply: 50 new certificates per registered domain per week and 5 duplicate certificates per week. It does not issue OV or EV certificates and offers no warranty.
    Open Let's Encrypt
  2. Cloudflare Universal SSL

    cloudflare.com

    4.8

    Automatic HTTPS at Cloudflare's edge for any domain whose DNS is proxied through Cloudflare.

    Best for
    Sites that already use Cloudflare DNS and want HTTPS with no server configuration.
    Free plan & limits
    Free and renewed automatically. It covers the root domain and one level of subdomains (example.com and *.example.com). Deeper subdomains need Advanced Certificate Manager (10 USD per month). For end-to-end encryption, add a free Cloudflare Origin CA certificate (valid up to 15 years) on your server and set SSL mode to Full (strict).
    Open Cloudflare Universal SSL
  3. ZeroSSL

    zerossl.com

    4.4

    Certificate authority with ACME support and a web interface for manual certificates.

    Best for
    Users who want to issue a certificate through a web interface, or a second ACME provider as a fallback.
    Free plan & limits
    Through ACME (acme.sh uses ZeroSSL by default), certificates are free with 90-day validity. Through the web interface, the free plan allows 3 certificates of 90 days each, without wildcards or multi-domain certificates. A free account is required.
    Open ZeroSSL
  4. Google Trust Services

    pki.goog

    4.3

    Google's public certificate authority, available through ACME.

    Best for
    Teams on Google Cloud, or anyone who wants a backup CA in case Let's Encrypt has an outage.
    Free plan & limits
    Free DV certificates through ACME, with validity of up to 90 days. You need a Google Cloud project to get External Account Binding (EAB) credentials. Wildcards are supported through DNS-01.
    Open Google Trust Services
  5. Caddy (automatic HTTPS)

    caddyserver.com

    4.6

    Web server that obtains and renews certificates on its own.

    Best for
    New self-hosted servers and reverse proxies where you don't want to manage certificates at all.
    Free plan & limits
    Open source (Apache 2.0). It gets certificates from Let's Encrypt and falls back to ZeroSSL, renews them automatically and redirects HTTP to HTTPS. Ports 80 and 443 must be reachable from the internet. Wildcards require a DNS provider plugin.
    Open Caddy (automatic HTTPS)

02 — Comparison

Side by side

Scroll sideways to see every tool. The first column stays pinned.

Feature / CriterionLet's EncryptCloudflare Universal SSLZeroSSLGoogle Trust ServicesCaddy
Validation typeDVDV (edge)DVDVDV (via LE / ZeroSSL)
Validity90 daysManaged by Cloudflare90 daysUp to 90 days90 days
Auto-renewalYes (Certbot / ACME)Yes, automaticYes (ACME)Yes (ACME)Yes, built in
WildcardYes (DNS-01)Yes, one levelACME onlyYes (DNS-01)Yes (DNS plugin)
Account requiredNoYes (Cloudflare)YesYes (Google Cloud)No
Works without changing DNSYesNo (DNS must be on Cloudflare)YesYesYes
OV / EV availableNoNoPaid onlyNoNo

03 — Guide

How to install a free SSL certificate step by step

  1. Check whether your host already includes it

    Cloudflare Pages, Netlify, Vercel, GitHub Pages and most cPanel hosts (AutoSSL) issue certificates automatically. If your host does, all you need is to enable 'Force HTTPS'.

  2. Point DNS to the server and open ports 80 and 443

    The HTTP-01 challenge needs the domain's A or AAAA record to point to the server and port 80 to be reachable. Behind a firewall or for a wildcard certificate, use the DNS-01 challenge with your DNS provider's API token instead.

  3. Issue the certificate with Certbot

    On Ubuntu with Nginx, run: sudo apt install certbot python3-certbot-nginx, then sudo certbot --nginx -d example.com -d www.example.com. Certbot proves you control the domain, installs the certificate and edits the server block for you.

  4. Test automatic renewal

    Run sudo certbot renew --dry-run. The systemd timer that Certbot installs checks twice a day and renews certificates within 30 days of expiry. Let's Encrypt no longer sends expiry emails, so monitor certificate expiry yourself, for example with an uptime monitor.

  5. Force HTTPS and verify the grade

    Redirect all HTTP traffic to HTTPS with a 301, then add HSTS (Strict-Transport-Security: max-age=31536000) once everything loads over HTTPS. Test the site on SSL Labs (ssllabs.com/ssltest) and aim for an A grade with TLS 1.2 and 1.3 only.

04 — FAQ

Common questions

Is a free SSL certificate as secure as a paid one?

Yes, for encryption. A free DV certificate and a paid one use the same RSA or ECDSA keys and the same TLS protocols, and browsers show the same padlock for both. Paid OV and EV certificates only add verification of the organization's identity and a warranty. Browsers stopped showing a special indicator for EV in 2019.

Are there hidden costs in a free SSL certificate?

No, for Let's Encrypt, Cloudflare Universal SSL and Google Trust Services. The only costs are paid extras: Cloudflare Advanced Certificate Manager (10 USD per month) for subdomains deeper than one level, and ZeroSSL paid plans for more than 3 certificates issued through its web interface. Some shared hosts sell 'SSL' for 50–100 USD per year even though they support free AutoSSL, so check before you pay.

Why do free certificates last only 90 days?

Short validity limits the damage if a private key leaks, and it pushes everyone toward automated renewal. The industry is moving further in this direction: the CA/Browser Forum has approved a gradual cut in the maximum certificate lifetime to 47 days by 2029, so even paid certificates will need automated renewal.

Can I get a free wildcard SSL certificate?

Yes. Let's Encrypt and Google Trust Services issue wildcard certificates (*.example.com) through the DNS-01 challenge, for example: certbot certonly --dns-cloudflare -d '*.example.com'. Cloudflare Universal SSL also covers one level of subdomains automatically.

What are the best alternatives if I need advanced features?

For OV or EV certificates with organization validation and a warranty, use a commercial CA such as DigiCert or Sectigo, or a reseller (OV usually costs about 50–200 USD per year). To manage hundreds of domains, use cert-manager on Kubernetes with Let's Encrypt, or a managed service such as AWS Certificate Manager, which is free for certificates used on AWS load balancers and CloudFront.

Scores reflect our own assessment of free-tier value. Prices and limits change, so check them on each provider's site before you buy.

esc

↑↓ move↵ open⌘K or / anywhere