DrivenHost

Knowledgebase / Security & SSL

Get your free SSL certificate working

How to check your free AutoSSL certificate in cPanel, force visitors onto https, and fix the warnings that sometimes remain afterwards.

Every domain hosted with us gets a free SSL certificate issued automatically. Most of the time you do not have to do anything: the certificate is requested and installed for you shortly after the domain starts pointing at our servers. This guide shows you how to confirm the certificate is in place, force your visitors onto https, and diagnose things when the padlock refuses to appear. You need your cPanel login, and your domain's DNS must already point at your hosting account.

Check SSL/TLS Status

  1. Log in to cPanel and open SSL/TLS Status, under the Security section.
  2. Find your domain in the list. A green padlock next to it means a valid certificate is installed. Note that www.yourdomain.com and yourdomain.com are listed separately; both should show green.
  3. If a domain shows a red padlock or an error, tick the box beside it and click Run AutoSSL. This queues a fresh certificate attempt.
  4. Wait a few minutes, then refresh the page. The log link next to each domain tells you exactly why an attempt failed, which is usually a DNS problem.

Certificates renew automatically before they expire, so once a domain shows green you should not need to touch this screen again.

Force https

Having a certificate is not the same as using it. Visitors typing your bare domain will still land on http unless you redirect them.

  1. In cPanel, open Domains, under the Domains section.
  2. Find your domain and switch on Force HTTPS Redirect. The toggle only becomes available once a valid certificate is installed.
  3. Test it: browse to http://yourdomain.com and confirm you are redirected to the https version with a padlock in the address bar.

If you run WordPress, also update the site URL in Settings so WordPress itself generates https links.

About mixed-content warnings

Sometimes the certificate is valid and the redirect works, yet the browser shows "not secure" or a broken padlock anyway. That is mixed content: your page loads over https but something inside it (an image, stylesheet, or script) is still referenced with a plain http:// address, so the browser downgrades its verdict on the whole page. The fix is editing those references to https:// or to protocol-relative paths; your browser's developer console (F12, Console tab) lists the offending URLs, and WordPress users can update old links with a search-and-replace plugin.

If it didn't work

  • DNS is not pointing here yet. AutoSSL has to verify your domain over the internet, so a domain still pointing at an old host or still propagating will fail. Confirm your nameservers or A record first, then re-run AutoSSL.
  • The www version fails but the bare domain works (or vice versa). Both names need DNS records pointing at us. Add the missing record and try again.
  • A redirect loop or an old certificate keeps appearing. If your domain sits behind a proxy service such as a CDN, its SSL mode has to match; set it to full or strict rather than flexible.

If the padlock still will not cooperate, contact us at /support with your domain and we'll trace it.

Stuck partway through? Support is answered by the engineers who run the servers, around the clock.

← All guides

No sales team. No scripts.

Tell us what you're running.
We'll tell you what it needs.

Migrations are free, quotes are written, and the engineer who replies is on the team that will run your server.