Purpose
This post applies SSL configuration for any domain in the exact order required to avoid issuance failures and certificate conflicts.
SSL must be configured after DNS and nameserver prerequisites are in place and before any mail authentication steps begin.
This sequence is strict. Do not reorder or skip steps.
Scope and Applicability
- Applies to any Domain
Prerequisites
- Required DNS records exist and resolve correctly
- Nameservers are assigned at the registrar
- DNS changes have had sufficient time to propagate
- No mail authentication has been configured yet
If DNS propagation is incomplete, stop and wait before continuing.
Moving Domains Only: SSL Removal Tasks
If this domain previously existed on another server, any existing SSL certificates must be unassigned there before proceeding.
Follow this procedure only if applicable:
If this is a brand‑new domain or no SSL existed for it previously, this “Moving Domains” section won’t apply to this domain.
DirectAdmin USER SSL Configuration
Begin SSL setup at the DirectAdmin User level.
Follow the canonical procedure in the exact order provided:
This step requests and assigns the SSL certificate for the domain.
DirectAdmin ADMIN SSL Configuration
After completing user‑level SSL configuration, confirm required settings at the Admin level.
Follow the canonical procedure:
This ensures SSL behavior is consistent and properly enforced server‑wide for this domain.
If SSL Issues Occur
If certificate issuance fails or behaves unexpectedly, review the following checklist before retrying:
Do not repeatedly try to reissue certificates without resolving the underlying issue.
SSL Validation Checks
Confirm the following before proceeding:
- A valid SSL certificate is issued for the account domain
- Go to this domain’s (default website Home landing page) & confirm it has a default HTTPS page showing.
- Confirm HTTPS access works without warnings.
- Confirm the certificate is assigned and active
- Only applicable for the Account Domain
- Confirm you can logon to DirectAdmin using “https” & the DirectAdmin URL includes the account domain name (e.g., server.<account domain>) and not needing to use its IP address.
Stop Point
Do not perform any of the following yet:
- Enable DKIM, SPF, or DMARC
- Configure mail routing or authentication
Mail identity steps depend on SSL being stable and verified first.
Next step:
• For the initial, Account Domain, see Confirm Redis and Other Supporting Services.
• If this is an Additional Domain, see Confirm Supporting Services for an Additional Domain.

