SSL on WP Engine
How SSL certificates are managed on WP Engine, how to check your certificate status, and what to do if you see a security warning.
WP Engine provides free SSL certificates for all sites. SSL is what lets your website use https://, so browsers show it as a secure connection instead of flagging it "Not secure". That matters for visitor trust, and Google looks at whether pages are served securely. On WP Engine, SSL is largely managed automatically.
Quick summary
For most custom domains, WP Engine installs and renews SSL certificates automatically. Certificates are managed through the User Portal. Unless you use a certificate bought from another company, you don't need to do anything to keep them active. If you see a security warning, let us know and we'll investigate.
How SSL works on WP Engine
Most domains on WP Engine use its Advanced Network or Global Edge Security. For those, the certificate is installed automatically through Cloudflare, so you don't need to add one. Domains still pointed at WP Engine's older Legacy Network can use a free Let's Encrypt certificate instead. When your custom domain is properly connected to your WP Engine site:
- WP Engine provides an SSL certificate (automatically on the Advanced Network and Global Edge Security).
- The certificate is installed and the site is served over HTTPS.
- Plain
http://visits can be redirected tohttps://. Whether that happens automatically depends on how the domain is set up, so check it on your site. If it doesn't happen, tell us and we'll get it switched on. - Certificates WP Engine manages renew automatically, with no manual action required.
Checking SSL status in the User Portal
Log in to the WP Engine User Portal at my.wpengine.com.
Open the environment that uses the domain. On the Sites page, click the environment's name (usually Production).
Click Domains in the environment's left-hand menu.
Check the SSL column. A green check next to the domain means a certificate is installed. For certificates added by hand (Let's Encrypt or one you bought), the SSL page in the same menu lists each one with its status. It should say Active.
You can also check quickly in your browser: look for https:// at the start of the address, and no "Not secure" warning in the address bar.
Adding SSL to a new or custom domain
When you connect a new domain to WP Engine:
Add the domain to your site in the WP Engine User Portal (on the environment's Domains page). WP Engine recommends doing this before you change any DNS records.
Make sure DNS is configured correctly. The domain must point to WP Engine before it can be secured. See how DNS & hosting fit together.
Check the certificate. On the Advanced Network or Global Edge Security, the certificate is installed automatically. On the Legacy Network, request one from the environment's SSL page: click Add certificate, then Get Let's Encrypt. Certificates usually install within a few minutes, but it can take up to 24 hours.
If you see a "Not secure" warning
Common causes on WP Engine sites:
- DNS not fully propagated — the domain may not have fully pointed to WP Engine yet. Give it some time and check again.
- Mixed content — some elements (images, scripts) may still load over
http://. This requires a WordPress configuration fix. - Certificate not yet issued — SSL may still be in the process of being provisioned.
Contact us if the issue persists and we'll diagnose it.
Common questions
Does WP Engine SSL cost extra?
Free SSL certificates are included on all WP Engine plans.
Does WP Engine support custom SSL certificates?
Yes. WP Engine supports custom (paid) SSL certificates for organizations that require them (e.g. Extended Validation, wildcard or multi-domain certificates). Not every plan allows them. They don't renew automatically, so a new certificate has to be added each time yours is renewed. This is for specialist use cases — most sites don't need this.
How do I know when my certificate is expiring?
For certificates WP Engine manages, renewal is automatic, so you generally don't need to monitor this. The exception is a certificate bought from another company: that one needs renewing by hand before it expires, so keep an eye on the date your certificate provider gives you.
Related guides
- What is SSL & HTTPS?
- The WP Engine User Portal explained
- How DNS & hosting fit together
- SSL on Flywheel
- SSL on Kinsta
Need a hand?
Learn more
Last updated