A wildcard such as *.example.com covers one label level and does not automatically cover the base domain or deeper names.
An SSL certificate confirms control of a domain and encrypts traffic to the service named in the certificate. It does not make vulnerable application code safe, and it only covers the hostnames included in the certificate.
Key information
| Covered | www.example.com and shop.example.com when *.example.com is included. |
|---|---|
| Not automatically covered | example.com unless listed separately. |
| Not covered | a.b.example.com because that is two labels below the wildcard. |
| Private key | Must be protected and installed only where authorised. |
Before you start
- Confirm the active product or addon and the domain or user it protects.
- Record the current settings before changing them.
- Allow for DNS caching and avoid making unrelated DNS changes during the same maintenance window.
How to use this service
- List every public hostname before choosing certificate names.
- Include the base domain separately when both example.com and *.example.com are required.
- Use a multi-domain certificate or additional wildcard for deeper or unrelated domains.
- Choose an appropriate validation method and ensure DNS changes are controlled.
- Install the certificate and complete chain on each authorised endpoint.
- Test every hostname and renew before expiry using the same key-handling and validation controls.
Confirm the result
- The service dashboard shows the intended setting or activation state after reload.
- A live test from a separate session or device confirms that the customer-facing service works as expected.
Common problems
| Symptom | Likely cause | What to do |
|---|---|---|
| Certificate issuance fails. | The domain does not resolve to the hosting server, an incorrect AAAA record exists, or validation requests are redirected or blocked. | Confirm public A and AAAA answers, allow HTTP validation to reach the account and retry only after DNS is correct to avoid rate limits. |
| The browser still shows an old or invalid certificate. | A proxy, CDN, alternate hostname or cached connection is presenting a different certificate. | Check the certificate actually served for each hostname and test both IPv4 and IPv6 paths before reinstalling anything. |
Important notes
- Make production changes in a planned window, keep the old configuration recorded and avoid changing several dependent services at the same time.
When to contact Tudor Internet
Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:
- The addon service and protected domain or user
- The plan or licence level
- The time the issue started and exact message
- Screenshots with credentials, tokens and personal data removed
Related articles
- Choose an SSL certificate
- Generate a certificate signing request
- Install a paid SSL certificate
- Renew an SSL certificate
- Choose between Let’s Encrypt and a paid SSL certificate
Last reviewed: 2026-07-18.