Confused about Secure SSL/TLS Email Certs


My VPS has no need for https, but I would like to use Secure SSL Email. The cPanel setting for incoming and outgoing servers would be

It was recommended I purchase a wildcard cert for and ... which I did.

Now I'm told that a single cert on would have been adequate. Since cert renewal is coming up, I'm wondering if I could save a bundle of money by getting a single domain cert for just

What's right - Single or wildcard cert?
Hi woodp,

I would think it depends on how you and your clients configure your email client. If everyone configures for then you need SSL for If configured for then you need SSL for Some clients like using their own domain name for their SMTP in which case this wouldn't work for them. The self-signed certificate works you simply get a pop-up stating that it's an untrusted certificate (at least Outlook did this), it just means that the cert wasn't generated by a trusted SSL vendor. least Outlook did this...
Yea, and if you have users try and set up their own email you can expect more support calls. Some email clients have SSL enable by default, like iPhones (which they all should) so if your server's SSL is self-signed you can expect a call "What is this server not trusted message?".

I don't know how much your'e paying and I don't usually try to toot on my reseller plan with godaddy but when it may help someone...
Single Domain SSL cert: $49.99/yr
Get a 5 subdomain cert for just $59.99/yr -This option would probably be best for you so you can cover both, and and have a couple others if the need arrises.
Wildcard for $199.95/yr

I personally, for the primary domain on my server, use a wildcard cert so it covers SSL with email, WHM, Cpanel access, and of course my website without any annoying "not a trusted certificate" crap.

Hope that helps.
Thanks guys, but you didn't answer my question - single or wildcard?

Attached is a screen capture from the email setup in cPanel. Note for insecure email, a user would use and there would be no browser or Outlook warning - Insecure email without a cert ... But for SSL email using ports 465 and 993, regardless of the users domain, every user would use for smtp and imap.

When I first set up SSL email a year ago, I was told I needed a wildcard cert to cover *and*

Or ... could I just purchase a single cert for (and ignore and get the exact same results?

So, SSL email at a KH VPS running cPanel - single or wildcard cert?


If you only want your SSL cert to cover your then yes and single will cover your needs. However, the purchase of a "Single Domain SSL Cert" in my experience only covers "" and "" so that's likely why you were told to get a wildcard cert. If you can find a company that will sell you a single and let you choose what subdomain to use it for, then that will work. If not, then you may be able yo go for the "multiple domain cert" which should allow you to cover just the domains you want while saving you some money.