Blog

Web Security articles

Wildcard vs Multi-Domain (SAN) SSL Certificates

Wildcard SSL certificate or multi-domain SAN? How each one covers names, their security trade-offs, and how to choose for your subdomains.

4 min read Web Security

Once a business runs more than one website or subdomain, a question comes up at renewal time: buy one certificate per name, one wildcard SSL certificate, or one multi-domain certificate listing everything? All three work. The right answer depends on how many names you have, how often they change, and how many servers will hold the private key.

How certificates list the names they cover

Every modern certificate contains a Subject Alternative Name (SAN) field: a list of hostnames the certificate is valid for. Browsers check the address you visit against this list. A "single-domain" certificate typically has two entries, such as example.com and www.example.com. Wildcard and multi-domain certificates are simply different ways of filling in that same list.

What a wildcard SSL certificate covers

A wildcard certificate has an entry like *.example.com. The asterisk matches any single label in that position, so one certificate covers:

  • www.example.com
  • shop.example.com
  • portal.example.com, and any subdomain you create later

It does not cover:

  • example.com itself (the bare domain). Most CAs add it as a second SAN entry automatically, but check.
  • Second-level subdomains such as eu.shop.example.com. You would need *.shop.example.com as well.
  • Any other domain, such as example.in.

Wildcards are available as Domain Validated (DV) or Organization Validated (OV) certificates. Industry rules do not allow wildcard Extended Validation (EV) certificates. Free wildcard certificates from Let's Encrypt are possible but require DNS-based validation, meaning your renewal tooling needs to create TXT records in your DNS automatically.

What a multi-domain (SAN) certificate covers

A multi-domain certificate, often sold as a "SAN" or "UCC" certificate, lists specific names explicitly. Those names can belong to entirely different domains:

example.com
www.example.com
example.in
www.example.in
mybrand.co.uk
mail.example.com

Commercial CAs usually price these by the number of names, with a base number included. You can add or remove names by reissuing the certificate, which generally keeps the same expiry date. Multi-domain certificates can be DV, OV or EV, and some CAs allow wildcard entries inside them (for example *.example.com plus example.in).

Wildcard vs SAN: side-by-side

WildcardMulti-domain (SAN)
CoversUnlimited subdomains, one level, one domainA specific list of names, any domains
Adding a new subdomainAutomatic, no reissueReissue with the new name
Different domainsNoYes
EV availableNoYes
Reveals your hostnamesNo, only the wildcard is listedYes, every name is visible in the certificate
ValidationDNS-based for ACME issuanceAny method, per name

The security trade-off: one key in many places

The biggest difference is not price but blast radius. A certificate is only as safe as its private key. If one wildcard certificate is installed on the website, the mail server, a staging box, a marketing agency's landing page server and a load balancer, then the key is copied to all of them. A compromise of the least secure of those machines exposes a key that can impersonate every subdomain, including ones that handle logins or payments.

Multi-domain certificates share this risk when they are deployed to many servers. The safer pattern, regardless of type, is to give each server or service its own certificate covering only the names it serves. With automated issuance through ACME, managing many certificates costs very little effort, which makes this much more practical than it used to be.

A related point: all publicly trusted certificates are recorded in public Certificate Transparency logs. A SAN certificate therefore reveals every hostname on it, including internal-sounding ones like vpn.example.com or staging.example.com. A wildcard does not list individual subdomains. That is a minor privacy benefit, not real security; attackers can usually discover subdomains through DNS anyway.

Renewal and management differences

Day-to-day effort differs too. A wildcard needs no changes when you launch a new subdomain, but automated renewal depends on DNS API access, so a change of DNS provider can silently break it. A multi-domain certificate must be reissued whenever the list changes, and if one name on it fails validation at renewal (for example, a domain that has lapsed or moved), the whole renewal can fail until you remove that name. Keep the list tidy and remove names you no longer use.

Which should you choose?

  • Many subdomains under one domain, all on the same platform (for example a SaaS product giving each customer customer.example.com): a wildcard is the natural fit.
  • Several different domains for one website (country domains, old brand names that redirect): a multi-domain certificate keeps them on one renewal cycle.
  • Different services on different servers: separate certificates per service, ideally automated, limit the damage if one server is compromised.
  • Need EV: multi-domain EV is your only multi-name option.

Whichever you pick, keep a record of every place the certificate is installed. At renewal time, every copy must be replaced, and a missed load balancer or mail server is a common cause of "we renewed it but the site still shows expired". After renewing, test each hostname with an SSL checker to confirm the new certificate and chain are live, and check your subdomains' DNS records with a DNS lookup so none point at a server you forgot.

Key takeaways

  • A wildcard covers every subdomain one level deep on a single domain, but not the bare domain unless listed.
  • A multi-domain (SAN) certificate covers an explicit list of names across different domains.
  • Copying one certificate's private key to many servers widens the damage of any single compromise.
  • With automated issuance, separate certificates per service are often the most secure choice.

Need help with this?

Netifi helps businesses around the world with Web Security. Tell us what you are working on.