Provider repair guideReviewed 2026-08-07By HostWithShery technical editorial

Fix SSL for a domain in Plesk

Issue or select a certificate that covers the exact root and www hostnames, then enable it on the hosting subscription.

Start with evidence from your own domain before changing DNS, SSL or mail settings.
Check your own configuration

SSL Certificate Checker

This page is preconfigured with the SSL Certificate Checker that best matches this problem.

No accountPublic evidence only
Live public check
No account · Public configuration only
On this page

Fix SSL for a domain in Plesk: when this repair path applies

Issue or select a certificate that covers the exact root and www hostnames, then enable it on the hosting subscription. Use these steps when HTTPS fails while HTTP works, but first run the embedded diagnostic so the TLS, certificate and HTTPS evidence supports this provider-specific path rather than a neighboring DNS, TLS, application or mail cause.

Find the authoritative setting before editing

Plesk Websites & Domains, DNS Settings, Mail and SSL/TLS Certificates for the affected domain. For Fix SSL for a domain in Plesk, confirm the active nameservers and exact service owner before changing inspect certificate assignment. A DNS-looking screen at plesk has no public effect when another provider is authoritative for the zone.

Evidence to save for Fix SSL for a domain in Plesk

Record the current public state for inspect certificate assignment, renew/reissue if needed, test root and www. This gives the repair a before/after comparison and prevents a cached answer or a separate working service from being confused with the configuration that produced the symptom.

  • Inspect certificate assignmentTest the hostname actually requested, its certificate dates and SAN coverage, and the TLS handshake. Root and www can serve different certificates.
  • Renew/reissue if neededVerify renew/reissue if needed from the public Internet and compare it with the value the responsible provider says should be live.
  • Test root and wwwVerify test root and www from the public Internet and compare it with the value the responsible provider says should be live.
  • Verify redirect after TLS worksTest the hostname actually requested, its certificate dates and SAN coverage, and the TLS handshake. Root and www can serve different certificates.

Repair steps in plesk

Issue or select a certificate that covers the exact root and www hostnames, then enable it on the hosting subscription.

  • 1. Inspect certificate assignment. After this step, check the public value tied to inspect certificate assignment before changing another unrelated setting.
  • 2. Renew/reissue if needed. After this step, check the public value tied to renew/reissue if needed before changing another unrelated setting.
  • 3. Test root and www. After this step, check the public value tied to test root and www before changing another unrelated setting.
  • 4. Verify redirect after TLS works. After this step, check the public value tied to verify redirect after tls works before changing another unrelated setting.

Why this order matters for plesk

The sequence begins with the provider/authority decision, then moves through inspect certificate assignment, renew/reissue if needed, test root and www. That keeps the change scoped to the failed TLS, certificate and HTTPS path and avoids replacing nameservers, mail authentication or another healthy service just to make a provider dashboard indicator change.

Verify Fix SSL for a domain in Plesk

HTTPS should complete for the exact hostname, the certificate should be valid for that hostname, and root/www should follow the intended canonical redirect without a TLS error. Compare the same inspect certificate assignment and renew/reissue if needed evidence used before the change; a repair is complete when the public result agrees, not merely when the plesk interface reports that a save succeeded.

If plesk and the public result disagree

Check whether the edited zone is authoritative, whether the exact root/www/subdomain was changed, whether a proxy state alters the visible endpoint, and whether a prior TTL can still exist in recursive caches. Do not add a second conflicting inspect certificate assignment value to force validation.

Mistakes to avoid for this repair

Do not copy tenant-specific or region-specific values from another account, delete working email records during a website repair, change nameservers as a shortcut, or alter SSL/proxy modes without evidence from the origin. Fix SSL for a domain in Plesk should change only the settings required by this diagnosis.

Technical references

These primary standards and provider documents are used to verify the behavior described on this page. Provider dashboards can change, so use the current official value for tenant-specific DNS records rather than copying an example from another account.