๐Ÿ”’

SSL & Security

10 articles Allan Tanaka By Allan Tanaka

Install SSL certificates and keep your site secure.

How to Install a Free Let's Encrypt SSL in Plesk

Plesk makes it easy to secure your website with a free SSL/TLS certificate from Let's Encrypt. SSL encrypts the connection between your website and visitors, which is essential for security and required for modern web features. This guide covers installing and managing Let's Encrypt certificates. Prerequisites - Your domain must be publicly accessible and pointing to your Plesk server IP address. - The Let's Encrypt and SSL It! extensions must be installed. Contact your hosting provider if they are not available. Installing a Let's Encrypt Certificate 1. Log in to Plesk. 2. Go to Websites & Domains. 3. Click the domain you want to secure. 4. Under Security, click SSL/TLS Certificates. 5. Scroll to Install a free basic certificate provided by Let's Encrypt. 6. Click Install. 7. Configure the certificate options: - Email address: Used for notifications from Let's Encrypt. Defaults to your subscription email. - Secure the domain: Include the main domain name (recommended). - Include "www" subdomain: Secure www.yourdomain.com (recommended). - Secure webmail: Secure webmail.yourdomain.com (recommended). - Assign the certificate to mail domain: Secure mail services for this domain (recommended). 8. Click Get it free. 9. Plesk will generate and install the certificate. This usually takes a few seconds. Enabling SSL for Your Website 1. Go to Websites & Domains โ†’ click your domain. 2. Go to Hosting & DNS โ†’ Hosting Settings. 3. Ensure SSL/TLS support is checked. 4. From the Certificate dropdown, select the Let's Encrypt certificate. 5. Click OK. Your website is now accessible via https://. Wildcard Certificates If you have many subdomains, a wildcard certificate can secure them all at once: 1. When installing the certificate, select Issue wildcard certificate. 2. This secures *.yourdomain.com (all subdomains). 3. Plesk will automatically add a DNS record for verification. 4. If Plesk does not manage your DNS, you will need to add the TXT record manually at your DNS provider. Certificate Renewal - Let's Encrypt certificates are valid for 90 days. - The SSL It! extension automatically renews certificates 30 days before expiry. - No manual action is required for renewal. Important Notes - Let's Encrypt certificates are Domain Validated (DV) only โ€” they encrypt data but do not verify business identity. - If your domain is not resolving to the server, the certificate issuance will fail. - Let's Encrypt has rate limits: maximum 50 certificates per domain per week. Troubleshooting "Cannot issue a Let's Encrypt certificate": - Verify your domain is publicly accessible and resolves to the correct server IP. - Check at https://mxtoolbox.com/DNSLookup.aspx that the domain A record points to your server. Certificate is not applying to the website: - Go to Hosting Settings and ensure SSL/TLS support is enabled and the correct certificate is selected. "Too many certificates issued" error: - You have hit the Let's Encrypt rate limit. Wait one week before requesting additional certificates. Related Guides - Force HTTPS afterwards - Track expiry dates - Reissue if needed

How to Enable Two-Factor Authentication in Plesk

Two-factor authentication (2FA) adds an extra layer of security to your Plesk account. After entering your password, you will also need to enter a verification code from an authenticator app on your phone. This makes it much harder for unauthorized users to access your account, even if they know your password. Prerequisites - The Multi-Factor Authentication (MFA) extension must be installed. Contact your hosting provider if it is not available. - An authenticator app installed on your phone (e.g., Google Authenticator, Authy, or Microsoft Authenticator). Enabling 2FA 1. Log in to Plesk. 2. Go to Extensions โ†’ Multi-Factor Authentication. 3. Select Enable Multi-factor Authentication. 4. A QR code will appear on the screen. 5. Open your authenticator app on your phone. 6. Tap Add account โ†’ Scan barcode. 7. Point your phone camera at the QR code on the screen. 8. The app will add your Plesk account and begin generating 6-digit verification codes. 9. Enter the current verification code from the app into the Verification code field in Plesk. 10. Optionally enable "Remember Device" to skip 2FA on trusted devices for 30 days. 11. Click OK. Logging In With 2FA After enabling 2FA, the login process becomes: 1. Enter your username and password as usual. 2. Plesk will ask for a verification code. 3. Open your authenticator app and enter the current 6-digit code. 4. If you enabled "Remember Device", check the box to skip 2FA on this device for 30 days. Reconfiguring 2FA If you lose access to your authenticator app or get a new phone: 1. Go to Extensions โ†’ Multi-Factor Authentication. 2. Disable 2FA by clearing the Enable Multi-factor Authentication checkbox and clicking OK. 3. Re-enable 2FA and scan the new QR code with your new device. Important Notes - Save your backup codes when setting up 2FA. These can be used to log in if you lose access to your authenticator app. - Verification codes expire every 30 seconds. If your code is rejected, wait for a new one. - Your hosting provider may enforce 2FA for all users. In that case, you cannot disable it. Troubleshooting Cannot scan the QR code: - Use the manual setup option โ€” enter the secret key displayed below the QR code into your authenticator app. "Invalid verification code" error: - Make sure the time on your phone is set to automatic. 2FA codes are time-based. - Wait for a new code to generate (codes refresh every 30 seconds). Locked out of Plesk: - Contact your hosting provider to disable 2FA on your account. Related Guides - Restrict login by IP - Secure the site with SSL - Force HTTPS

How to Force HTTPS and Redirect HTTP to HTTPS in Plesk

After installing an SSL certificate, you should ensure that all visitors access your website securely via HTTPS. Plesk provides several options to enforce HTTPS, including permanent redirects from HTTP to HTTPS and a security header that tells browsers to always use HTTPS. Enabling Permanent HTTPS Redirect 1. Log in to Plesk. 2. Go to Websites & Domains โ†’ click your domain. 3. Go to Hosting & DNS โ†’ Hosting Settings. 4. Find Permanent SEO-safe 301 redirect from HTTP to HTTPS. 5. Check the box to enable it. 6. Click OK. Now all visitors who type http://yourdomain.com will be automatically redirected to https://yourdomain.com. Enabling HSTS (HTTP Strict Transport Security) HSTS tells browsers to always connect to your site via HTTPS, even if the user types http://: 1. Go to Websites & Domains โ†’ click your domain. 2. Go to Hosting & DNS โ†’ Hosting Settings. 3. Find Enable HSTS. 4. Check the box to enable it. 5. Click OK. Warning: Once HSTS is enabled, browsers will refuse to connect to your site via HTTP for the duration of the header. If you need to disable SSL temporarily, you may lock visitors out. Use with caution. Setting HTTPS as Default in Plesk 1. Go to Websites & Domains โ†’ click your domain. 2. Go to Hosting & DNS โ†’ Hosting Settings. 3. Under SSL/TLS support, select Redirect from HTTP to HTTPS (if available). 4. Click OK. Important Notes - The 301 redirect is SEO-safe โ€” search engines will update their index to use HTTPS. - Ensure your SSL certificate is properly installed and covers all subdomains before enabling permanent redirects. - After enabling HSTS, submit your site to the HSTS Preload List (hstspreload.org) for maximum security. Troubleshooting Redirect loop (infinite redirect): - This can happen if you have conflicting redirect rules. Check your Apache & nginx Settings for custom redirect directives. - Clear the redirect setting, save, then re-enable it. Some pages load without HTTPS: - Check for mixed content โ€” your pages may be loading resources (images, scripts) over HTTP. Use your browser developer tools to identify mixed content. Related Guides - Install a free SSL first - Use a custom certificate - Remove an old cert

How to Upload a Custom SSL Certificate in Plesk

If you have purchased an SSL certificate from a certificate authority (e.g., Comodo, DigiCert, Sectigo) or have an existing certificate, you can install it in Plesk. This is useful for Organization Validated (OV) or Extended Validation (EV) certificates, or when migrating a certificate from another server. Before You Begin - You need the following files from your certificate authority: - SSL certificate (yourdomain.crt or .pem) - CA bundle or intermediate certificates (if provided) - Private key (generated during the CSR process) - If you do not have a private key, you cannot install the certificate. The private key must match the certificate. Uploading the Certificate 1. Log in to Plesk. 2. Go to Websites & Domains โ†’ click your domain. 3. Under Security, click SSL/TLS Certificates. 4. Click Add SSL/TLS Certificate. 5. Select Upload the certificate files. 6. Upload the following: - Certificate: Your domain certificate file. - CA certificate: The intermediate/bundle certificate (if provided). - Private key: The private key file. 7. Click OK to upload and install the certificate. Alternative: Paste Certificate Text If you have the certificate content as text instead of files: 1. Click Add SSL/TLS Certificate. 2. Select Enter the certificate text. 3. Paste the certificate, CA bundle, and private key into the respective fields. 4. Click OK. Assigning the Certificate to Your Domain 1. Go to Websites & Domains โ†’ click your domain โ†’ Hosting Settings. 2. Ensure SSL/TLS support is checked. 3. From the Certificate dropdown, select your uploaded certificate. 4. Click OK. Important Notes - The private key must match the certificate. If they do not match, the certificate will not work. - Custom certificates are not automatically renewed. You must renew and replace them manually before they expire. - Check the certificate expiry date in SSL/TLS Certificates to monitor renewal dates. Troubleshooting "Unable to install certificate" error: - Verify the private key matches the certificate. - Ensure the certificate text includes the full BEGIN and END markers. - Check that the CA bundle is correctly pasted (all intermediate certificates). Browser shows "Not Secure" after installing: - Ensure the certificate is assigned to the domain in Hosting Settings. - Clear your browser cache and reload. Related Guides - Generate the CSR first - Or use free Let's Encrypt - Reissue a certificate

How to Protect Your Plesk Login with IP Access Restrictions

If you want to limit who can access your Plesk login page, you can restrict access by IP address. This prevents unauthorized login attempts from unknown locations. This guide covers how to set up IP-based access restrictions in Plesk. Restricting Plesk Access by IP Address 1. Log in to Plesk. 2. Go to Tools & Settings. 3. Under Security, click Restrict administrative access (or IP Access Restrictions). 4. Select Allow access only from the listed IP addresses. 5. In the IP addresses/subnet masks field, enter your IP address (e.g., 192.0.2.1). 6. To add multiple addresses, click Add or enter them separated by newlines. 7. You can also enter CIDR notation for IP ranges (e.g., 192.0.2.0/24). 8. Click OK. After enabling this, only the listed IP addresses will be able to access the Plesk login page. Finding Your Current IP Address - Visit https://whatismyipaddress.com to see your current public IP address. - Your IP address may change if you use a dynamic IP from your ISP. Consider using a range or VPN with a static IP. What If You Get Locked Out? If you accidentally lock yourself out: 1. Contact your hosting provider to remove the IP restriction. 2. Access the server via SSH and remove the restriction using Plesk CLI: plesk bin server_pref --update-web-interface-access-policy -access-policy allow Important Notes - IP restrictions apply to the Plesk control panel only, not to your website. - If your ISP assigns dynamic IP addresses, your IP may change and you could be locked out. - Be cautious when setting very narrow IP ranges โ€” you could accidentally lock out legitimate users. Troubleshooting "Access denied" after setting IP restrictions: - Your current IP address is not in the allowed list. Contact your hosting provider to add it. Cannot find "Restrict administrative access": - This option may not be available in the Customer Panel. Contact your hosting provider. Related Guides - Enable 2FA - Force HTTPS - Install SSL

How to Enable Hotlink Protection in Plesk

Hotlinking is when another website embeds your images or files using your URL, consuming your bandwidth every time someone visits their site. Here's how to block it in Plesk. For WordPress sites (WP Toolkit method) If your domain runs WordPress and you have WP Toolkit 3.5.0+, this is the easiest approach: 1. Log in to Plesk and click WordPress in the left sidebar. 2. Find your WordPress installation and click on it. 3. On the dashboard tab, toggle Enable hotlink protection to on. That's it โ€” WP Toolkit handles everything automatically. For all other sites (Apache & nginx method) On Plesk for Linux, there's no built-in hotlink protection GUI for non-WordPress sites. You'll add Apache rewrite rules instead. 1. Log in to Plesk. Go to Websites & Domains, find your domain, and click Apache & nginx Settings. 2. Scroll to Additional directives for HTTP and paste (replace example.com with your domain): RewriteEngine on RewriteCond %{HTTP_REFERER} !^$ RewriteCond %{HTTP_REFERER} !^http://(www\.)?example\.com(/)?.*$ [NC] RewriteRule \.(gif|jpg|jpeg|png|svg|webp|mp4)$ - [NC,F] 3. In Additional directives for HTTPS, paste the same rules but change http to https: RewriteEngine on RewriteCond %{HTTP_REFERER} !^$ RewriteCond %{HTTP_REFERER} !^https://(www\.)?example\.com(/)?.*$ [NC] RewriteRule \.(gif|jpg|jpeg|png|svg|webp|mp4)$ - [NC,F] 4. If nginx serves static files, either turn off Serve static files directly by nginx on this page, or add this to Additional nginx directives: location ~* \.(gif|jpe?g|png|svg|webp|mp4)$ { valid_referers none blocked example.com *.example.com; if ($invalid_referer) { return 403; } } 5. Click OK to save. Important notes - The !^$ rule allows empty referers โ€” don't remove it. Some browsers, privacy tools, and search crawlers don't send a referer. Blocking them can break Google image indexing. - Add any file types you want to protect: gif, jpg, png, svg, webp, mp4, pdf, zip. - If you use a CDN (like Cloudflare), add its domain as an allowed referer or it will block your own CDN-served content. Troubleshooting - Images broken on your own site: Check that your domain is included correctly in the RewriteCond lines. - Rules not working: Make sure Serve static files directly by nginx is off, or use the nginx directives instead. - 403 errors on all images: A typo in the domain name will block everything. Double-check spelling. Related Guides - Force HTTPS - Install SSL

How to Reissue and Replace an SSL Certificate in Plesk

If your SSL certificate has been compromised, contains incorrect details, or you've changed your server configuration, you may need to reissue and replace it. This guide walks you through the process in Plesk for both free Let's Encrypt and paid third-party certificates. Reissuing a free Let's Encrypt certificate Let's Encrypt certificates are the easiest to reissue since Plesk handles most of the process automatically through the SSL It! extension. 1. Log in to your Plesk control panel. 2. Go to Websites & Domains and select the domain that needs the new certificate. 3. Click SSL/TLS Certificates. 4. Find the currently installed Let's Encrypt certificate and click Reissue Certificate. 5. Confirm your domain coverage options: - Secure the main domain name - Include the www subdomain - Secure webmail (if applicable) - Include wildcard coverage (if needed) 6. Click Get it free to generate and install the new certificate. 7. Plesk will validate your domain automatically via DNS or HTTP and install the replacement certificate within a few minutes. Replacing a paid (third-party) SSL certificate For certificates purchased from providers like Comodo, DigiCert, or GoDaddy, the reissue process involves your certificate authority (CA). 1. Contact your certificate authority and request a reissue. You'll typically need to provide a reason (key compromise, domain change, etc.). 2. The CA may require a new CSR. To generate one in Plesk, go to Websites & Domains > your domain > SSL/TLS Certificates > Manage > Add SSL/TLS Certificate and fill in your details. 3. Submit the new CSR to your CA and complete their validation process. 4. Once you receive the reissued certificate files (.crt or .pem), return to Plesk. 5. Go to Websites & Domains > your domain > SSL/TLS Certificates. 6. Click Manage under "Download or remove existing certificates." 7. Click Add SSL/TLS Certificate, upload the new certificate file (and CA bundle if provided), then click Upload Certificate. 8. Go to Hosting Settings for the domain and select the newly uploaded certificate from the Certificate dropdown. 9. Click OK to apply. Important notes - Let's Encrypt certificates auto-renew every 60โ€“90 days when the SSL It! extension is active. Manual reissue is only needed if something goes wrong. - After replacing a paid certificate, verify the installation using an online checker like SSL Shopper. - If visitors see a security warning after replacement, clear your browser cache or wait a few minutes for the new certificate to propagate. - Always keep a backup of your private key โ€” without it, your certificate cannot be installed. Troubleshooting - Reissue button is greyed out: The certificate may still be processing. Wait a few minutes and refresh the page. - Let's Encrypt validation fails: Check that your domain's DNS points to the correct server IP and that no firewall is blocking port 80. - New certificate not showing: Make sure you selected it in Hosting Settings. The old certificate may still be assigned. - "Certificate chain is incomplete" error: You need to include the CA bundle (intermediate certificate) when uploading a paid certificate. Related Guides - Check expiry dates - Reinstall Let's Encrypt - Upload a replacement

How to View SSL Certificate Expiry Dates in Plesk

Every SSL/TLS certificate has an expiry date. Once it expires, browsers will show security warnings and your visitors will see "Not Secure" messages. Checking your certificate's expiry date in Plesk takes about 30 seconds โ€” here's how to do it. Step 1: Log in to Plesk Open your browser and go to your Plesk panel URL (usually https://yourdomain.com:8443). Enter your username and password to log in. Step 2: Navigate to your domain From the left sidebar, click Websites & Domains. Find the domain you want to check and click on its name to expand its options. Step 3: Open SSL/TLS Certificates Look for the SSL/TLS Certificates section on the domain dashboard. You'll see the current SSL status displayed here โ€” either a green padlock with the certificate name, or a warning if no certificate is installed. Click SSL/TLS Certificates to open the full certificate management page. Step 4: View the expiry date On the SSL/TLS Certificates page, you'll see details about the installed certificate, including: - Certificate name โ€” the label assigned to the certificate - Certificate authority โ€” who issued it (e.g. Let's Encrypt, DigiCert) - Valid from โ€” when the certificate was issued - Valid until โ€” the expiry date you're looking for - Secured components โ€” which parts of your domain are covered The Valid until date tells you exactly when your certificate expires. Step 5: Check from your browser (alternative method) You can also check the expiry date directly from any browser: - Visit your website using https:// - Click the padlock icon in the address bar - Click Certificate or Connection is secure (varies by browser) - Look for the Valid to or Expires field Important notes - Let's Encrypt certificates are valid for 90 days. If the SSL It! extension is active, Plesk renews them automatically 30 days before expiry. - Paid certificates (from DigiCert, Comodo, etc.) are typically valid for 1 year. These must be renewed manually or replaced with a free Let's Encrypt certificate. - Enable the Keep websites secured toggle on the SSL/TLS Certificates page so Plesk can automatically replace an expired paid certificate with a free Let's Encrypt one. - You can also use an external tool like SSL Shopper's SSL Checker to verify your certificate status from outside your server. Troubleshooting - No certificate shown: If the SSL/TLS Certificates page shows no installed certificate, your domain is not secured with SSL. Click Get it free to install a free Let's Encrypt certificate. - Certificate shows as expired: Click Reissue Certificate for paid certificates, or wait up to 1 hour for Let's Encrypt auto-renewal (if enabled). - Browser still shows old certificate: Clear your browser cache or wait a few minutes. SSL changes can take a short while to propagate. - SSL It! not showing: The SSL It! extension must be installed. Contact your hosting provider if it's missing from your panel.

How to Generate a CSR (Certificate Signing Request) in Plesk

A Certificate Signing Request (CSR) is encoded text you send to a Certificate Authority when purchasing a paid SSL certificate. It contains your domain name, organisation details, and public key. Here's how to generate one in Plesk. Step 1: Navigate to SSL/TLS Certificates Log in to Plesk. Click Websites & Domains, find your domain, and click SSL/TLS Certificates. Step 2: Add a new certificate Click Manage under "Download or remove existing certificates", then click Add SSL/TLS Certificate. Step 3: Fill in the certificate details Complete the form: - Certificate name โ€” a label to identify it (e.g. mydomain-2026) - Bits โ€” select 4096 (recommended) - Country โ€” two-letter code (e.g. ZA for South Africa) - State or province โ€” full name, not abbreviated - Location (city) โ€” your city - Organisation name โ€” your legally registered business name - Domain name โ€” the fully qualified domain (e.g. www.example.com). For wildcards, use *.example.com - Email โ€” contact email for the certificate Step 4: Generate the CSR Double-check all details โ€” errors mean starting over. Click Request. Plesk generates both a private key and CSR and stores them in your certificate repository. Step 5: Copy and submit the CSR Click the certificate name from the list. Scroll to the CSR section and copy the entire block, including the header and footer lines: -----BEGIN CERTIFICATE REQUEST----- (encoded text) -----END CERTIFICATE REQUEST----- Paste this into your Certificate Authority's order form. Once you receive the certificate file (.crt or .pem), return to Plesk to upload and install it. Important notes - Don't delete the private key. The CSR and private key are a matched pair. If you delete the key, the issued certificate won't work. - Domain name must be exact. A CSR for www.example.com won't cover example.com unless you get a SAN or wildcard certificate. - If you're using Let's Encrypt, you don't need a CSR โ€” Plesk handles everything automatically. Troubleshooting - "Add SSL/TLS Certificate" not visible: Look for "Advanced settings" instead of "Manage" โ€” it varies by Plesk version. - CSR section is empty: Make sure you clicked Request, not Self-Signed. - CA rejects the CSR: Check for typos in the domain or organisation name. Some CAs require exact business registration details. Related Guides - Upload the signed certificate - Reissue a certificate - Or use Let's Encrypt

How to Remove an SSL Certificate from Your Domain in Plesk

Need to remove an SSL certificate from a domain in Plesk? Whether you're replacing it, cleaning up old certificates, or moving a domain, here's how to unassign and delete certificates. Option A: Unassign a certificate (stop using it) This removes the certificate from active use without deleting the file itself. 1. Log in to Plesk. 2. Go to Websites & Domains, find your domain, and click SSL/TLS Certificates. 3. Click Unassign Certificate and confirm with OK. Your domain will revert to HTTP. Browsers will show a "Not Secure" warning. Option B: Delete a certificate from the repository To permanently remove a certificate file from Plesk: 1. First unassign the certificate (Option A above). 2. On the SSL/TLS Certificates page, click Manage under "Download or remove existing certificates". 3. Tick the checkbox next to the certificate you want to delete. 4. Click Remove and confirm the deletion. The certificate, private key, and CSR will be permanently deleted. Important notes - Unassign before deleting. You can't delete a certificate that's still assigned to a domain. - Let's Encrypt auto-reissue: If the Keep websites secured toggle is on, Plesk will issue a new Let's Encrypt certificate automatically. Turn this off first if you don't want a replacement. - Turn off HTTPS redirect. Removing SSL doesn't disable the HTTP-to-HTTPS redirect. If it's still active, visitors will get errors. Disable it under SSL/TLS Certificates for your domain. - HSTS warning: If you previously enabled HSTS, browsers will keep forcing HTTPS until the cached max-age expires โ€” even after you remove the certificate. - Back up paid certificates first. Download the certificate and private key files before deleting. You can't recover them from Plesk once removed. Troubleshooting - "Remove" button greyed out: The certificate is still assigned. Unassign it first. - Site shows HTTPS error after removal: Disable the HTTP-to-HTTPS redirect and clear your browser cache. - Certificate reappears after deletion: The Keep websites secured toggle is auto-issuing a new Let's Encrypt certificate. Disable it. Related Guides - Reissue instead - Install a fresh Let's Encrypt cert - Check expiry first