Both options enable encrypted HTTPS; choose based on validation, warranty/branding requirements and certificate coverage rather than encryption strength alone.
Applies to: Websites hosted with Tudor Internet
Compare the options
| Option | Best suited to | Key points |
|---|---|---|
| Let’s Encrypt | Most websites, blogs, portfolios and routine business sites. | Free, automated domain validation and renewal where DNS/HTTP remain valid. |
| Paid domain-validated certificate | Customers needing a separately purchased certificate or vendor support/warranty features. | Domain validation; renewal and installation must be managed. |
| Organisation-validated certificate | Organisations requiring the certificate order to validate organisational information. | Additional validation and lead time. |
| Wildcard certificate | Multiple first-level subdomains such as app.example.org and shop.example.org. | Does not normally cover deeper levels or a different base domain; protect the private key carefully. |
Decision steps
- List every hostname that needs certificate coverage.
- Confirm whether simple automated domain validation meets the requirement.
- Check whether organisation validation, a vendor warranty or a paid certificate is contractually required.
- Use Let’s Encrypt for normal hosted websites unless a specific paid-certificate feature is required.
- Follow the separate installation article for the selected certificate type.
Related articles
- Enable a free Let’s Encrypt SSL certificate
- Choose an SSL certificate
- Generate a certificate signing request
- Complete domain or organisation validation
- Install a paid SSL certificate
- Renew an SSL certificate
- Understand wildcard SSL certificate coverage
Last reviewed: 2026-07-25.