From “Not Secure” to a padlock — in four unhurried steps.
No CSRs, no key files, no server to log into. If you can paste one line into your registrar, you can secure your site — and then never think about it again.
Before
After
Publicly-trusted certificate active · auto-renews
Add your domain and AutoCertify checks it live as you go — you watch it move from pending → verifying → secured without ever guessing where things stand.
What actually happens, step by step.
Four steps, in order — because this really is a sequence. You do the first two; AutoCertify does the last two, then keeps doing them forever.
- 1
Add your domain
Sign in and type the domain that's showing “Not Secure.” No CSRs, no key files, no server access — AutoCertify figures out the rest.
shop.example.com Add domainNo CSRs, no key files, no server access.
- 2
Add one DNS record
We hand you a single CNAME and the exact steps for your registrar. Copy it, paste it, and our live check confirms it the moment it's in — or invite your developer to add it for you.
Add this one DNS record Waiting for DNS- Type
- CNAME
- Name
- _acme-challenge.shop.example.com
- Value
- shop.example.com.a1b2c3d4.dcv.cloudflare.com
- TTL
- 300
We generate the exact record for your registrar and give you copy buttons and step-by-step instructions — GoDaddy, Namecheap, Squarespace and the rest. Our live check confirms it the moment it lands.
GoDaddyNamecheapCloudflareSquarespaceWixPorkbunRather hand it off?
Send the exact record to your developer or DNS admin — they add one line and you're done.
- 3
Watch it go secure
AutoCertify validates control and issues a publicly-trusted certificate, usually within minutes. The “Not Secure” warning disappears, your site loads over trusted HTTPS, and you're done.
app.autocertify.net / shop.example.comSecuredshop.example.com
Domain · added just now
Add this one DNS record Detected- Type
- CNAME
- Name
- _acme-challenge.shop.example.com
- Value
- shop.example.com.a1b2c3d4.dcv.cloudflare.com
- TTL
- 300
Publicly-trusted certificate · active
Cloudflare for SaaS Managed CA · renews automatically
AutoCertify validates control and issues a publicly-trusted certificate through Cloudflare for SaaS — usually within minutes. The “Not Secure” warning disappears and the site loads over trusted HTTPS.
- 4
Never think about it again
From here it renews itself automatically, weeks ahead of every expiry. AutoCertify keeps checking that delegation and validity stay healthy and flags anything that needs a look — so a certificate never lapses on you.
Renews automatically, forever Delegation health-checked Status over signed webhooks
A domain reads “Secured” only when a real certificate is genuinely live.
AutoCertify never marks a hostname active until Cloudflare for SaaS confirms both the hostname and its SSL are live. No faked padlocks, no self-signed shortcuts, no “done” that isn’t. The status you see is the truth on the wire.
- Publicly-trusted certificates via Cloudflare for SaaS Managed CA — never self-signed
- Renewed automatically, weeks ahead of every expiry — a certificate never lapses on your watch
- Delegation health and certificate validity, surfaced in the dashboard and over signed webhooks
< 5 min
Typical time from CNAME to a live certificate
1
DNS record — added once, valid for every renewal
0
Keys, CSRs or servers you ever have to touch
∞
Renewals handled for you, for the life of the domain
Secure your first domain in the next five minutes.
Your first domain is free, forever — no card required. Add it, paste one record, and watch it go secure.