Purpose
This post applies SSL configuration for the account domain in the exact order required to avoid issuance failures and certificate conflicts.
SSL must be configured after DNS and nameserver prerequisites are in place and before any mail authentication steps begin.
This sequence is strict. Do not reorder or skip steps.
Scope and Applicability
- Applies to the Account Domain only
- Performed one time per VPS
- Establishes SSL behavior inherited by future domains
Prerequisites
- Required DNS records exist and resolve correctly
- Nameservers are registered and assigned at the registrar
- DNS changes have had sufficient time to propagate
- No mail authentication has been configured yet
If DNS propagation is incomplete, stop and wait before continuing.
Moving Domains Only: SSL Removal Tasks
If this domain previously existed on another server, any existing SSL certificates must be unassigned there before proceeding.
Follow this procedure only if applicable:
If this is a brand‑new domain or no SSL existed previously, skip this step.
DirectAdmin USER SSL Configuration
Begin SSL setup at the DirectAdmin User level.
Follow the canonical procedure in the exact order provided:
This step requests and assigns the SSL certificate for the domain.
DirectAdmin ADMIN SSL Configuration
After completing user‑level SSL configuration, confirm required settings at the Admin level.
Follow the canonical procedure:
This ensures SSL behavior is consistent and properly enforced server‑wide.
If SSL Issues Occur
If certificate issuance fails or behaves unexpectedly, review the following checklist before retrying:
Do not repeatedly reissue certificates without resolving the underlying issue.
SSL Validation Checks
Confirm the following before proceeding:
- A valid SSL certificate is issued for the account domain
- Go to this account domain’s (default website Home landing page) & confirm it has a default HTTPS page showing.
- The certificate is assigned and active
- Confirm you can logon to DirectAdmin using “https” & the path includes the domain name (e.g., server.<account domain>) and not using its IP address.
- Confirm HTTPS access works without warnings.
Stop Point
Do not perform any of the following yet:
- Enable DKIM, SPF, or DMARC
- Configure mail routing or authentication
Mail identity steps depend on SSL being stable and verified first.
Proceed to the next post to confirm Redis and other supporting services are running correctly before continuing with mail configuration.

