Applies to: All plans
Before you start: You need access to cPanel (single sign-on from your service page in the client area). Your domain should already be pointed at Maxinodes — its DNS must resolve to our hosting node before a certificate can be issued.
Every Maxinodes plan includes free SSL through AutoSSL (Let's Encrypt). It issues certificates automatically and renews them before they expire, so most sites never need anything done by hand. Use this article to confirm a domain is covered, see when a certificate expires, or re-run AutoSSL if a certificate is missing.
Check your SSL status in cPanel
- Log in to cPanel (see How to log in to cPanel).
- Go to cPanel -> Security -> SSL/TLS Status.
- You will see a list of every domain and subdomain on the account, each with a status:
- A green padlock or "valid" badge means the domain has a working certificate.
- The expiry date is shown next to each entry — AutoSSL renews well before this, so you do not act on it yourself.
- A warning or "not covered" status means that domain currently has no certificate.
Result: You can see at a glance which domains are protected by HTTPS and which still need a certificate.
Confirm AutoSSL coverage
On this same SSL/TLS Status page, AutoSSL automatically tries to cover all of your domains and subdomains. A domain is covered once it shows a valid certificate with a future expiry date.
A domain may not be covered yet if:
- It is brand new (give AutoSSL up to a few hours after the DNS resolves).
- Its DNS does not point to our hosting node (an A record to
185.185.49.198and an AAAA record to2a00:7c80:0:286:c::10— when your domain uses our nameservers, both are created for you). Check this first if a certificate will not issue — see How to manage DNS records in your client area. - It is a domain you only use for email through Microsoft 365 or Google Workspace — that domain does not need a web certificate from us, and your mailboxes are secured by your email provider, not by AutoSSL.
Re-run AutoSSL to reissue a missing certificate
If a domain shows no certificate but its DNS is correct, ask AutoSSL to try again:
- In cPanel -> Security -> SSL/TLS Status, tick the box next to the domain(s) you want to cover (or use the select-all option).
- Select Run AutoSSL (sometimes shown as Run AutoSSL for the selected items).
- Wait a few minutes — AutoSSL checks the domain and installs a certificate if it can.
- Refresh the page to confirm the status has turned valid.
Result: The domain now shows a valid certificate and your site loads over HTTPS.
Troubleshooting this task
-
AutoSSL keeps failing for a domain. The most common cause is DNS — the domain must resolve to
185.185.49.198before a certificate can issue. Confirm your nameservers arens1.maxinodes.comandns2.maxinodes.comand that the A record points to our node. (Customer websites are served over both IPv4 and IPv6 (dual-stack): when your domain uses our nameservers, both the A record to 185.185.49.198 and the AAAA record to 2a00:7c80:0:286:c::10 are created for you, and AutoSSL covers both addresses.) -
The certificate is valid but the site still shows "Not Secure". That is usually mixed content (hard-coded
http://links), not a missing certificate — see Why does my site show 'Not Secure' or mixed content?. - You bought a certificate elsewhere. AutoSSL is not for purchased certificates — see How to install a third-party or purchased SSL.
- Still stuck. Start a chat and tell us the exact domain — on Managed plans we will sort the certificate for you.
Comments
0 comments
Please sign in to leave a comment.