Picture an agency managing 25 client websites. Some clients have one domain, others have a domain plus a dozen subdomains, and a few have several brands under separate domains. Buying a certificate for each one gets expensive and messy fast. That's where wildcard and multi domain SSL come in, and choosing the wrong one creates its own problems.
How each one works
A wildcard certificate covers one domain and all its first-level subdomains. A certificate for *.example.com secures shop.example.com, blog.example.com, and any other subdomain you add later.
A multi domain SSL certificate (also called SAN or UCC) covers a list of different domain names on a single certificate, such as example.com, another-brand.com, and client-three.net.
There's also a hybrid, the multi-domain wildcard, which covers several domains plus their subdomains.
Which one fits which situation
- One client, many subdomains: wildcard.
- Many different domains, few subdomains each: multi-domain.
- Several domains that also need subdomains: multi-domain wildcard.
The limits nobody mentions
Wildcards cover only one level. *.example.com secures shop.example.com but not eu.shop.example.com. Most providers include the bare domain as a free extra name, though it's worth confirming. And EV certificates can't be issued as wildcards at all.
Multi-domain certificates have their own quirks. Every domain on the certificate is visible to anyone who inspects it, and issued certificates are logged in public Certificate Transparency records. If you put Client A and Client B on the same certificate, each can see the other's domain. Adding or removing a domain also means reissuing the certificate, and if one client leaves you'll need to reissue for everyone else.
A wildcard adds a different risk: the same private key often ends up on several servers, so a single leak affects every subdomain.
Comodo wildcard SSL, Sectigo wildcard SSL, and DigiCert wildcard SSL compared
Comodo wildcard SSL and Sectigo wildcard SSL both come from the same CA, since Comodo's certificate business became Sectigo, so the practical differences are product tiers, validation level, and packaging. A DigiCert wildcard SSL is typically sold with organization validation and higher warranty levels, and is aimed at businesses that want that extra assurance. Check the validation type on each product page, because it decides both the price and the paperwork.
What to expect from a cheap wildcard SSL
A cheap wildcard SSL is usually a domain-validated certificate, issued quickly with no company paperwork. For most agencies' client sites that's enough for encryption. If a client needs a verified company identity or higher warranty, plan for organization validation and a higher price.
Buy wildcard SSL or buy multi domain SSL? A quick decision guide
Ask four questions:
- How many domains, and how do they change? Frequent additions favor a wildcard for subdomains and separate certificates for unrelated clients.
- Do clients share a certificate? If privacy between clients matters, use separate certificates.
- How sensitive is the key? The more servers hold a wildcard key, the higher the exposure.
- What validation do you need? DV is fastest; OV takes documentation.
Renewal and automation
Both types can be automated. Wildcards need DNS validation for ACME, while multi-domain certificates need each name validated separately. With short certificate lifetimes arriving, set up automation early, especially if you're managing dozens of client sites.
FAQs
1. Is a wildcard SSL better than a multi-domain SSL?
Neither is universally better. A wildcard is useful when one domain has multiple subdomains, while a multi-domain certificate is useful when you need to secure several different domains.
2. Can a wildcard SSL certificate secure multiple domains?
No. A standard wildcard certificate covers one domain and its first-level subdomains. If you need multiple unrelated domains, a multi-domain certificate is generally more appropriate.
3. What is the difference between wildcard and multi-domain SSL?
Wildcard SSL protects one domain and its subdomains, while multi-domain SSL protects multiple specified domain names on a single certificate.
4. Is a multi-domain SSL certificate suitable for agencies?
It can be, especially when an agency manages several domains. However, putting multiple clients on one certificate can create privacy and management considerations if domains need to remain separated.
5. Can wildcard and multi-domain SSL certificates be automated?
Yes. Both can be automated. Wildcard certificates commonly use DNS validation for ACME-based automation, while multi-domain certificates require validation for each domain.
Top comments (0)