To choose an SSL certificate, decide two things: how much the certificate authority should check about you (DV, OV or EV), and how many domain names it must cover (one name, all subdomains, or several domains). For most blogs and small business sites, a free domain-validated certificate is enough. All types use the same encryption; you pay for identity checks, coverage and support.
This guide covers the choice itself. If you still wonder whether a blog needs HTTPS at all, read why you need an SSL certificate for a blog first.
What does an SSL certificate actually do?
An SSL certificate (today the protocol is really TLS, but everyone still says SSL) does two jobs. It lets the browser and your server set up an encrypted link, so nobody in between can read or change the data. It also proves that the server really belongs to the domain in the address bar.
A certificate authority (CA) issues the certificate. A CA is a company or nonprofit that browsers trust, such as Let's Encrypt, DigiCert, Sectigo or GlobalSign. Before it signs your certificate, the CA checks something about you. That check is the main difference between certificate types.
DV, OV and EV: which validation level do you need?
The validation level tells you what the CA checked. It does not change how strong the encryption is.
| Type | What the CA checks | Typical use |
|---|---|---|
| DV (Domain Validated) | Only that you control the domain | Blogs, small sites, most business sites |
| OV (Organization Validated) | Domain plus a real, registered organization | Companies that want their name in the certificate details |
| EV (Extended Validation) | A stricter check of the legal business | Banks and firms with a policy that requires it |
Domain Validated (DV)
A DV certificate only proves that you control the domain. The CA asks you to place a file on the server or add a DNS record. Issuing takes minutes and can run fully on autopilot. Let's Encrypt only issues DV certificates, and its FAQ says it has no plans to offer OV or EV.
Organization Validated (OV)
With OV, the CA also checks that your company exists, often through public business records and a phone call. Visitors only see this if they click the padlock and open the certificate details. Most never do.
Extended Validation (EV)
EV used to show the company name in a green bar next to the URL. That is no longer true. In Chrome 77 (2019), Google moved the EV company name out of the address bar and into the page info panel behind the padlock, and Firefox made a similar change. So EV no longer gives you a special look in the browser. Buy it only if a bank, partner or internal policy asks for it.
Single, wildcard or multi-domain: how many names?
The second choice is coverage. Count the names you need before you buy, because a certificate that covers too little means a second purchase later.
- Single-domain: covers one name, usually with and without www (for example example.com and www.example.com).
- Wildcard: covers one level of subdomains, written as *.example.com. It suits a site with blog.example.com, shop.example.com and so on. It does not cover deeper levels like a.b.example.com.
- Multi-domain (SAN): lists several different names in one certificate, such as example.com, example.net and example.org. SAN stands for Subject Alternative Name, the field that holds the extra names.
Let's Encrypt supports both wildcard and multi-name certificates for free. For a wildcard, it requires the DNS-01 challenge, which means your host or DNS provider must let a tool add a temporary DNS record. Many shared hosts handle this for you; some do not.
Free or paid: what do you really get for the money?
A free Let's Encrypt DV certificate and a paid DV certificate encrypt traffic in the same way. Browsers trust both. Visitors see the same padlock. So for a blog, a portfolio or a small shop that uses a payment provider, free is usually the right choice.
Paid certificates make sense in a few cases:
- You need OV or EV because a policy, partner or tender demands it.
- Your host or server setup cannot renew certificates on its own, and you want a longer manual cycle.
- You want vendor support on the phone, or a warranty that the CA offers.
One thing to plan for: Let's Encrypt certificates last 90 days, and the project now also offers optional six-day certificates. That short life only works with automatic renewal. Most control panels (cPanel, hPanel, Plesk) and tools such as Certbot renew on their own. Check that renewal is switched on, because an expired certificate shows a full-page browser warning.
How to choose an SSL certificate in five steps
- List every hostname you serve: the main domain, www, and any subdomains like mail, shop or cdn.
- Pick the coverage: one name, a wildcard for many subdomains, or a SAN certificate for several domains.
- Pick the validation level: DV unless someone requires OV or EV.
- Check your host first. Most hosts include free DV certificates in the control panel. Turn that on before you buy anything.
- Test and redirect. Run your domain through a checker such as SSL Labs, then send all HTTP traffic to HTTPS with a permanent redirect.
For the last step, our guide on how to create a 301 redirect in .htaccess shows the exact lines for an Apache server.
Common mistakes when buying a certificate
- Paying for EV to get a "green bar". That bar is gone in Chrome and Firefox.
- Forgetting www or a subdomain. A visitor who types the missing name gets a scary warning.
- Letting a certificate expire. Set up auto-renewal, and add a calendar reminder for paid ones.
- Mixed content. If the page loads over HTTPS but an image or script still uses http://, browsers may block it or drop the padlock. Update old links in your theme and posts.
- Thinking SSL fixes rankings. Google called HTTPS "a very lightweight signal" when it announced it in 2014. It helps trust, but content and links matter far more.
What about SEO after the switch?
The certificate type has no effect on rankings. Google does not rank an EV site above a DV site. What matters for search is that every page loads over HTTPS without errors, that old HTTP URLs redirect to the HTTPS version, and that your internal links and sitemap use the new URLs. After you switch, check Search Console and run a crawl to catch old links; the steps in how to fix broken links work well here.
In short: to choose an SSL certificate, start with the free DV option your host offers, match the coverage to your hostnames, and pay for OV or EV only when someone outside your site asks for it. Then spend the money you saved on content.
Frequently asked questions
Is a free SSL certificate safe enough?
Yes. A free Let's Encrypt certificate uses the same encryption standards as a paid DV certificate, and all major browsers trust it. The difference is support and identity checks, not security of the connection. Just make sure auto-renewal works.
Does an EV certificate still show the company name in the browser?
Not in the address bar. Since Chrome 77 in 2019, the company name sits in the page info panel that opens when you click the padlock. Firefox made a similar change, so most visitors never see it.
Do I need a wildcard certificate for www?
No. A normal single-domain certificate usually covers both example.com and www.example.com. You need a wildcard only when you run several subdomains such as blog, shop or app and want one certificate for all of them.

