Every domain on Flashcloud hosting gets a free Let's Encrypt SSL certificate, issued automatically about 5 minutes after your domain points to us. That certificate renews itself too. AutoSSL runs on a schedule in the background and reissues certificates before they expire, so in the normal case you never have to touch anything.
If you're seeing a certificate warning or an expired-cert error, the fix is almost always to check that your domain's DNS still points at Flashcloud and that nothing is blocking validation. The details are below.
The renewal cycle
AutoSSL doesn't wait until a certificate is about to expire to act. It checks domains on the server on a regular interval and reissues any certificate approaching expiration, well before that becomes a problem. If one renewal attempt fails, AutoSSL tries again on its next pass.
This is separate from PHP or domain-level settings you manage in the portal. SSL renewal isn't a toggle you flip, it's a background process tied to your domain's hosting.
How AutoSSL validates your domain
To reissue a certificate, AutoSSL has to prove you actually control the domain. It does this with domain control validation, the same check that happened the first time your certificate was issued. In practice, that means your domain's DNS needs to resolve to the server where your hosting lives.
Renewal problems usually start here. If you recently changed nameservers, moved a domain, or edited a DNS record and validation fails, the certificate can't renew and you'll eventually see a browser warning. Nameservers are managed from the domain's page in the portal (Domains → your domain → DNS), and up to 5 can be set there. If you need to add or edit individual DNS records, like an A record or CNAME, that's a different screen: Services → your hosting → DNS Zone Editor. Mixing these two up is a common source of confusion, since "DNS" appears in both places but they control different things.
If you're troubleshooting a validation failure, start by confirming the domain resolves where you expect. Tools like dig or nslookup will show you what's actually being returned, which is useful for spotting a stale or incorrect record before it becomes an expired-certificate problem.
Checking certificate status
If a browser is showing a certificate warning, most of the time it's one of these:
- DNS was recently changed and hasn't fully propagated yet
- A CNAME or A record is pointing somewhere other than your hosting
- The domain was recently transferred or had its nameservers changed and the new setup hasn't settled
DNS propagation itself isn't instant. Changes can take anywhere from a few minutes to a couple of days to be visible everywhere, depending on caching along the way and the TTL set on the record. That's normal, and it's the most common reason a fresh DNS change and a certificate renewal briefly don't line up.
SSL certificates vs. domain settings: a common mixup
AutoSSL is strictly about the certificate itself: issuing and renewing it. It has nothing to do with:
- Registrar lock or ID protection, which are domain registration settings, not certificate settings
- The domain's auto-renew toggle, which controls whether the domain registration itself renews each year, separate from the SSL certificate that secures it
- Cloudflare's SSL/TLS mode, if you have the CDN enabled on that domain. Cloudflare's proxy sits in front of your origin certificate, and its own mode setting (Flexible, Full, or Full (strict)) determines how it talks to the certificate AutoSSL issued
A domain can have a perfectly valid, freshly renewed certificate and still show a browser warning if Cloudflare's SSL/TLS mode doesn't match what your origin server is actually serving. If you're running the CDN, that's worth checking as a separate step from anything on the hosting side.
When to contact support
If DNS is confirmed correct and pointing at Flashcloud, propagation has had time to settle, and you're still seeing a certificate warning after a day or two, that's worth a ticket. Open one from Support → New ticket in the portal, or reach us through live chat. A real person will help you track down what's failing.