Get a free website with any plan

See how
CPANEL

How SSL renewal works (AutoSSL)

Last updated

IN SHORT

AutoSSL on Flashcloud automatically renews your free Let's Encrypt SSL certificate before it expires. The system runs on a regular background schedule without manual toggles. For renewal to succeed, your domain's DNS must point to your Flashcloud hosting so domain control validation can complete.

Every domain on Flashcloud hosting gets a free Let's Encrypt SSL certificate, issued automatically about 5 minutes after your domain points to us. That certificate renews itself too. AutoSSL runs on a schedule in the background and reissues certificates before they expire, so in the normal case you never have to touch anything.

If you're seeing a certificate warning or an expired-cert error, the fix is almost always to check that your domain's DNS still points at Flashcloud and that nothing is blocking validation. The details are below.

The renewal cycle

AutoSSL doesn't wait until a certificate is about to expire to act. It checks domains on the server on a regular interval and reissues any certificate approaching expiration, well before that becomes a problem. If one renewal attempt fails, AutoSSL tries again on its next pass.

This is separate from PHP or domain-level settings you manage in the portal. SSL renewal isn't a toggle you flip, it's a background process tied to your domain's hosting.

How AutoSSL validates your domain

To reissue a certificate, AutoSSL has to prove you actually control the domain. It does this with domain control validation, the same check that happened the first time your certificate was issued. In practice, that means your domain's DNS needs to resolve to the server where your hosting lives.

Renewal problems usually start here. If you recently changed nameservers, moved a domain, or edited a DNS record and validation fails, the certificate can't renew and you'll eventually see a browser warning. Nameservers are managed from the domain's page in the portal (Domains → your domain → DNS), and up to 5 can be set there. If you need to add or edit individual DNS records, like an A record or CNAME, that's a different screen: Services → your hosting → DNS Zone Editor. Mixing these two up is a common source of confusion, since "DNS" appears in both places but they control different things.

If you're troubleshooting a validation failure, start by confirming the domain resolves where you expect. Tools like dig or nslookup will show you what's actually being returned, which is useful for spotting a stale or incorrect record before it becomes an expired-certificate problem.

Checking certificate status

If a browser is showing a certificate warning, most of the time it's one of these:

  • DNS was recently changed and hasn't fully propagated yet
  • A CNAME or A record is pointing somewhere other than your hosting
  • The domain was recently transferred or had its nameservers changed and the new setup hasn't settled

DNS propagation itself isn't instant. Changes can take anywhere from a few minutes to a couple of days to be visible everywhere, depending on caching along the way and the TTL set on the record. That's normal, and it's the most common reason a fresh DNS change and a certificate renewal briefly don't line up.

SSL certificates vs. domain settings: a common mixup

AutoSSL is strictly about the certificate itself: issuing and renewing it. It has nothing to do with:

  • Registrar lock or ID protection, which are domain registration settings, not certificate settings
  • The domain's auto-renew toggle, which controls whether the domain registration itself renews each year, separate from the SSL certificate that secures it
  • Cloudflare's SSL/TLS mode, if you have the CDN enabled on that domain. Cloudflare's proxy sits in front of your origin certificate, and its own mode setting (Flexible, Full, or Full (strict)) determines how it talks to the certificate AutoSSL issued

A domain can have a perfectly valid, freshly renewed certificate and still show a browser warning if Cloudflare's SSL/TLS mode doesn't match what your origin server is actually serving. If you're running the CDN, that's worth checking as a separate step from anything on the hosting side.

When to contact support

If DNS is confirmed correct and pointing at Flashcloud, propagation has had time to settle, and you're still seeing a certificate warning after a day or two, that's worth a ticket. Open one from Support → New ticket in the portal, or reach us through live chat. A real person will help you track down what's failing.

Common questions

Why is my browser showing an SSL certificate warning?

Your domain's DNS is likely pointing away from Flashcloud, or recent changes have not finished propagating. AutoSSL must confirm domain control by resolving your DNS to the hosting server before it reissues a certificate. Verify that your nameservers, A records, and CNAMEs point to your Flashcloud hosting.

Do I need to turn on AutoSSL renewal in the portal?

No, AutoSSL renews certificates automatically in the background. It is not a toggle you turn on in your portal or PHP settings. The system checks server domains on a set interval and attempts renewal well before expiration.

Why is my site showing an SSL warning when using Cloudflare?

Your Cloudflare SSL/TLS encryption mode does not match the certificate on your hosting server. Cloudflare sits in front of your site and uses Flexible, Full, or Full (strict) modes to communicate with Flashcloud. A mismatch triggers a browser warning even if AutoSSL renewed the certificate properly.

How long do DNS updates take to fix a failing certificate?

DNS propagation takes anywhere from a few minutes to a couple of days. The timing depends on caching along the route and the TTL set on your records. AutoSSL will attempt validation again on its next scheduled pass once records resolve.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.