SSL Certificates
This guide walks you through enabling SSL certificates on Hostworld cPanel hosting using AutoSSL. You will point your domain at Hostworld, run AutoSSL to request certificates, and enable HTTPS redirection. The guide also covers troubleshooting common issues like DNS resolution failures and blocked validation paths.
To put your site on HTTPS now: point your domain to your Hostworld cPanel hosting, run AutoSSL in cPanel, then enable Force HTTPS Redirect. If you already forced HTTPS, turn that off first.
Before you start
- Your domain must resolve to your Hostworld cPanel server. Either use our nameservers or point A and AAAA records to your hosting IP.
- Keep plain HTTP reachable for validation. Do not enable Force HTTPS or HSTS until the certificate has issued.
- If you use a CDN or WAF, pause features that rewrite or block traffic during issuance, for example Always Use HTTPS or aggressive bot protection.
Step 1: Point your domain at Hostworld
Use Hostworld nameservers
- At your domain registrar, set the nameservers to:
ns1.serverworld.uk, ns2.serverworld.uk, ns3.serverworld.uk, ns4.serverworld.uk (type them exactly as shown). - Wait for DNS to update, then continue to Step 2.
- Undo: if you need to roll back while you fix something, change the nameservers back to the previous values, then switch again when you are ready.
Keep DNS elsewhere
- Update the domain’s A record to your hosting IPv4 and the AAAA record to your hosting IPv6, if you use IPv6. Remove any stray AAAA that points to another provider.
- Confirm the domain resolves to your Hostworld server, then continue to Step 2.
- Undo: restore the prior A or AAAA if you must revert while investigating, then point back to us when fixed.
Step 2: Run AutoSSL in cPanel
- In cPanel, open Security then SSL/TLS Status (or the unified SSL/TLS Certificates page on newer versions).
- Use Run AutoSSL to request certificates for the listed domains. In current cPanel versions AutoSSL uses Let’s Encrypt and validates via HTTP using files under
/.well-known/acme-challenge/. - Wait for the statuses to show the domains as secured, then move to Step 3. AutoSSL also installs certificates for webmail and mail services.
- Undo: if you triggered AutoSSL before fixing DNS or redirects, you do not need to cancel anything. Correct the issue, then run AutoSSL again or wait for the next automatic run.
Step 3: Enable HTTPS redirection
- In cPanel, open Domains and toggle Force HTTPS Redirect on for the domain and any subdomains you serve.
- Visit
https://yourdomainto confirm it loads over HTTPS. - Undo: if this causes a loop or blocks access, turn the Force HTTPS toggle back off, fix the cause, then re‑enable it.
If it does not work
- DCV failed due to DNS. If AutoSSL says the domain resolved to an IP that is not on this server, fix the A and AAAA records or use our nameservers. A stray AAAA is a common culprit. After correcting DNS, run AutoSSL again.
- Redirects or security rules blocked the ACME path. Ensure you can fetch a real file under
http://yourdomain/.well-known/acme-challenge/from the public internet. Temporarily disable Force HTTPS, HSTS, CMS security plugins that block unknown paths, and any CDN or WAF features that force HTTPS or challenge bots. Exclude/.well-known/from rewrites. Run AutoSSL again, then re‑enable your rules. - Browser still shows Not secure after enabling HTTPS. That is usually mixed content. Update all asset links to
https://. In WordPress, set the WordPress Address and Site Address to HTTPS, then update any hard‑coded HTTP URLs in themes, plugins and the database.
If you have checked these and AutoSSL still will not issue after the domain resolves to us, open a support ticket so we can review the logs and DCV status.
What next
For a fuller explanation of how AutoSSL works, DCV methods, CAA and rate limits, see our guides section: guides. If you run your own server stack and need SSL on a VPS, see our VPS guides for the right route on that platform. If you prefer us to look, open a support ticket and we will check it.
Common questions
Do I need to buy an SSL certificate?
No. Hostworld provides free SSL certificates via AutoSSL, which uses Let's Encrypt. You just need to run AutoSSL in cPanel to request and install them.
What do I do if AutoSSL says domain validation failed?
Check that your domain's A and AAAA records point to your Hostworld server, or switch to Hostworld nameservers. Remove any stray AAAA records pointing elsewhere. After fixing DNS, run AutoSSL again.
Why does my browser still show Not secure after enabling HTTPS?
This is usually mixed content, where some resources load over HTTP instead of HTTPS. Update asset links to use HTTPS. In WordPress, set the WordPress Address and Site Address to HTTPS and fix any hard-coded HTTP URLs.
What if a CDN or WAF is blocking the SSL certificate validation?
Pause features that rewrite or block traffic during issuance, such as Always Use HTTPS, aggressive bot protection, or rules that exclude the /.well-known/ path. Re-enable them after AutoSSL completes.
Was this article helpful?
0 people found this helpful