📄
Webhosting

Wildcard SSL Certificate: What Is It and When Do You Need One?

📅 7 octobre 2026 ✏️ 7 octobre 2026 ⏱ 5 min leestijd

What is a wildcard SSL certificate, when do you need one, and how do you install it? Practical explanation with step-by-step plan and frequently asked questions.

A wildcard SSL certificate secures a main domain and all its subdomains with a single certificate. Instead of requesting a separate certificate for each subdomain, you cover, for example, mail.yourdomain.com, shop.yourdomain.com, and test.yourdomain.com all with a single certificate on *.yourdomain.com. Handy if you work with multiple subdomains, but not always necessary: for most websites, a regular SSL certificate works just fine.

What exactly is a wildcard SSL certificate?

A normal SSL certificate secures exactly one domain name, for example www.yourdomain.com. If you also want to secure mail.yourdomain.com or shop.yourdomain.com, you would in theory need separate certificates for that. A wildcard certificate solves this by using the asterisk (*) as a placeholder: *.yourdomain.com automatically covers all first-level subdomains.

Important to know: a wildcard certificate only covers subdomains one level below the main domain. *.yourdomain.com secures shop.yourdomain.com, but not automatically test.shop.yourdomain.com. For that, you would need a separate wildcard on *.shop.yourdomain.com.

One wildcard certificate*.domain.comwwwshopmail

One wildcard certificate secures the main domain and all subdomains at one level.

When do you need a wildcard certificate?

A wildcard certificate is especially useful in specific situations. Ask yourself whether any of the points below apply to you:

  • You use many subdomains that change regularly, for example with a SaaS platform with a subdomain per customer.
  • You don’t want to manually request a new certificate every time you add a subdomain.
  • You manage multiple services (webshop, mail, portal) on subdomains of the same main domain.

Do you only have a handful of fixed subdomains, for example just www and mail? Then a wildcard is often not necessary. Free SSL certificates nowadays usually cover multiple domains at once as well, without necessarily needing a wildcard. At Tandata, you get free SSL with every web hosting package, which is more than sufficient for most websites.

💡 Tip: Not sure if you need a wildcard? First make a list of all the subdomains you currently use and expect to add in the near future. That way you’ll immediately see whether a wildcard is worth it.

Requesting and installing a wildcard certificate

Requesting and installing a wildcard certificate is largely the same as for a normal SSL certificate, with one important difference: domain validation happens via DNS instead of via a file on the web server.

1

Choose the right certificate provider

Not every free SSL solution supports wildcard certificates by default. Check with your hosting provider whether this is available, or request a wildcard certificate from a certificate authority.

2

Request the certificate on the main domain

You request the certificate on *.yourdomain.com. Don’t forget to also add the bare main domain (without asterisk), otherwise yourdomain.com itself won’t be covered.

3

Validate via a DNS TXT record

Because the certificate covers multiple subdomains, validation cannot be done via a file on the server. You add a TXT record to your DNS settings to prove you own the domain.

4

Install the certificate in Plesk

After validation, you upload the certificate (or link it automatically) under SSL/TLS Certificates in Plesk, and assign it to the main domain and the subdomains you want to secure.

5

Check all subdomains

Open each subdomain in the browser and check whether the padlock icon appears without warnings. Also don’t forget to check your email settings if they run on a subdomain.

Common mistakes and points to watch out for

A few pitfalls to keep in mind with wildcard certificates:

  • Overlooking an expired certificate: because a single certificate covers so many subdomains, your entire infrastructure goes down when it expires, instead of just one site. Keep a close eye on the expiration date.
  • Wrong expectation about depth: as mentioned earlier, *.yourdomain.com does not cover subdomains of subdomains. If you need those, you’ll have to arrange that separately.
  • DNS changes not applied correctly: validation via DNS requires precision. An incorrect TXT record will cause the request to fail. Check your domain name settings carefully before submitting the request.
  • Forgetting email: if your email runs on a subdomain covered by the wildcard, that subdomain also needs to actually be linked to the certificate. If you work with business email, check whether mail servers connect properly via SSL/TLS.

Frequently Asked Questions

Is a wildcard certificate more secure than a normal certificate?

Not necessarily more secure in terms of encryption, but it is more practical with many subdomains. The risk is that if the private key is leaked, in theory all subdomains become vulnerable instead of just one.

Can I combine a wildcard certificate with free SSL?

That depends on your hosting provider. Not every free SSL solution offers wildcard support. Check this before assuming it works automatically.

Does a wildcard certificate also work for new subdomains I add later?

Yes, as long as the new subdomain is at the same level (for example new.yourdomain.com), it automatically falls under the existing wildcard certificate, without you needing to request it again.

Do I need to change my DNS for a wildcard certificate?

Yes, for validation you need to temporarily add a TXT record to your DNS. Once the certificate is approved, you can remove this record again.

Conclusion

A wildcard SSL certificate is especially valuable if you work with multiple or changing subdomains and don’t want to keep requesting separate certificates. For most websites with a limited number of fixed subdomains, a regular SSL certificate works just fine. Not sure what your situation requires? Check out the options in our knowledge base or get in touch.

View web hosting →

Was dit artikel nuttig?