SSL on Kinsta
How Kinsta manages free SSL certificates via Cloudflare, how to check your certificate status, and what to do if you see a security warning.
Kinsta provides free SSL certificates for all sites through Cloudflare. Every domain you add and verify on Kinsta gets a certificate automatically — keeping your visitors' connections secure and your site trusted by browsers.
Quick summary
Kinsta issues free SSL certificates via Cloudflare for every verified domain. Certificates are added automatically once your domain is verified, and renew automatically as long as a DNS record Kinsta gives you (the _acme-challenge CNAME record) stays in place. To send all visitors to the secure version of your site, turn on Force HTTPS in MyKinsta. The site's Domains page in MyKinsta shows each domain and flags any that need attention.
How Kinsta SSL works
Kinsta integrates with Cloudflare's global network for SSL. When your domain is added to a Kinsta site:
- Once the domain is verified, Kinsta adds a free Cloudflare SSL certificate for it. The certificate includes wildcard support, so it can cover the domain's subdomains too.
- The certificate is installed and your site can load over HTTPS.
- To redirect all HTTP traffic to HTTPS, turn on Force HTTPS under Tools in MyKinsta. This isn't automatic.
- Certificates renew automatically, as long as the
_acme-challengeCNAME record stays in your DNS.
This applies to your primary domain and any additional domains you verify on the site.
Checking SSL status in MyKinsta
Log in to MyKinsta and open your site.
Go to the Domains page. This lists all domains connected to your site.
Check each domain in the list. A checkmark next to a domain means it's pointed to Kinsta correctly. If a Renew SSL or Fix domain error button appears next to a domain, its certificate needs attention.
You can also verify directly in your browser:
- The URL should start with
https:// - There should be no "Not secure" warning
Adding SSL for a new domain
When you add a new custom domain to your Kinsta site:
Add the domain in MyKinsta (Domains page of your site, then Add domain).
Add the DNS records Kinsta shows you. Kinsta gives you records to verify the domain and to point it at Kinsta. You add them wherever your DNS is managed. See how DNS & hosting fit together.
Kinsta will automatically add the SSL certificate once the domain is verified. Verification usually takes a few minutes, depending on your DNS settings.
What to do if you see a security warning
If you see "Not secure" or another security warning on your Kinsta site, possible causes include:
- DNS not yet fully updated — DNS changes can take anywhere from a few minutes to a day or two to reach everyone, depending on your DNS settings.
- Mixed content — some page elements (images, scripts) are loading over HTTP. This needs a WordPress configuration fix.
- Certificate in the process of being issued — wait a few minutes after adding a new domain.
- The
_acme-challengerecord was removed — without it the certificate can't renew. Kinsta emails a warning 30 days before the certificate expires.
Contact us if the issue persists and we'll diagnose it quickly.
Common questions
Does Kinsta SSL cost extra?
No. Free SSL via Cloudflare is included on all Kinsta plans for all verified domains.
Does Kinsta support custom SSL certificates?
Yes. If you've bought a certificate from another provider, you can add it in MyKinsta from the site's Domains page (the three-dot menu next to the domain, then Add custom SSL certificate). This is a specialist use case. Kinsta doesn't send expiry reminders for custom certificates, so you renew them with your provider and upload the new one yourself.
Will my SSL certificate expire?
Certificates do expire, but Kinsta renews its free ones automatically as long as the _acme-challenge CNAME record stays in your DNS. If that record is missing, Kinsta emails you and shows a notification in MyKinsta 30 days before expiry, so you can add it back.
What's the difference between Cloudflare SSL and a traditional SSL certificate?
Kinsta's free certificate is issued through its Cloudflare integration, renews itself while that DNS record stays in place, and covers your subdomains. A certificate you buy has to be renewed with the provider you bought it from and uploaded to MyKinsta again, and Kinsta won't remind you when it's due. For virtually all business websites, the free certificate does the same job.
Related guides
- What is SSL & HTTPS?
- The MyKinsta dashboard explained
- How DNS & hosting fit together
- SSL on Flywheel
- SSL on WP Engine
Need a hand?
Learn more
Last updated