Do I need a separate SSL certificate for each subdomain?
Certificate types
A single-name certificate protects one exact host name, such as www.example.com. A wildcard certificate protects names like shop.example.com and blog.example.com, but it covers only one subdomain level. A multi-name certificate, often called a SAN certificate, lists several specific names in one certificate.
Choosing the right type depends on how many subdomains you run and how they are structured. Many small sites need only one or two names, so a single certificate may be enough.
- Single-name: one exact host
- Wildcard: one level of subdomains
- Multi-name: a list of chosen host names
Planning your setup
List every subdomain you use before buying a certificate, including ones used only for testing or internal tools. Adding names later can mean reissuing the certificate, which takes time.
Confirm the certificate covers the exact names visitors type, and test each site in a browser. Mismatched names cause warnings that look like security problems.
Consider a wildcard certificate if you plan to add many subdomains and want to avoid reissuing. Single-name certificates are simpler and can be enough for a small site with one or two hosts. Renewal reminders help prevent gaps in coverage no matter which type you choose. Check the issuer's current options before buying, since names and product types change.
Common mistakes
- Buying a single-name certificate and expecting it to cover every subdomain.
- Assuming a wildcard covers deeper levels such as a.b.example.com.
