24/7 Validation Support · Certificates issued in minutes
0
MULTI-DOMAIN WILDCARD SSL

Multi-Domain Wildcard SSL Certificates

Secure several primary domains and all their first-level subdomains under one certificate. Multi-domain wildcard SSL certificates start from $150/yr at Renewal SSL, with DV options issued in minutes and OV options in 1–2 business days. Combines the multi-name flexibility of SAN with the unlimited subdomain power of wildcard.

MAXIMUM COVERAGE POWER

Secures multiple base domains (example.com, brand.net) AND every first-level subdomain (*.example.com, *.brand.net) from a single issued certificate.

SCALE UP TO 250 SAN SLOTS

Supports up to 250 SAN entries. Each SAN slot can hold either a regular FQDN or a wildcard (*.) domain. Unlimited server licenses included with zero extra fees.

PRODUCT CATALOG

Multi-Domain Wildcard Certificates

Ultimate SSL consolidation for enterprise portfolios, SaaS multi-tenancy, and agencies.

Multi-Domain Wildcard

Organization Validation

Sectigo Multi Domain Wildcard Certificate (1 CN Wildcard + 2 SANS Wildcard)

Price range: $300,00 through $570,00

Multi-Domain Wildcard

Organization Validation

Sectigo UCC Wildcard (1 CN Wildcard + 2 SANS Wildcard)

Price range: $300,00 through $570,00

Multi-Domain Wildcard

Organization Validation

Digicert Secure Site Multi Domain Wildcard (1 Single + 2 Wildcard)

Price range: $3.561,92 through $9.795,28

HYBRID ARCHITECTURE

What a Multi-Domain Wildcard SSL Certificate Is

Combining SAN flexibility with wildcard scalability in a single X.509 certificate.

HYBRID POWER

Two Products in One

Instead of buying separate SAN and wildcard certificates, cover several distinct domains and all subdomains under each from one certificate with one private key.

• Replaces 4+ individual certificates • Covers example.com & *.example.com • Covers brand.net & *.brand.net • One installation across server fleet
SAN FLEXIBILITY

Up to 250 Total SANs

The SAN extension lists every domain covered. Entries can be standard FQDNs or wildcard entries, scaling up to 250 SAN slots at checkout or via free reissues.

• Default packages: 3 or 4 SANs included • Scale up to 250 SAN items • Mix wildcard & regular SANs • Free unlimited reissuances
ASTERISK RULES

One Subdomain Level Rule

The wildcard character (*) covers exactly one subdomain level (*.domain.com covers shop.domain.com, not dev.app.domain.com). Add deeper wildcards as separate SANs.

• *.domain.com covers level-1 subdomains • For nested: add *.sub.domain.com • Bare domain added as separate SAN • 256-bit symmetric session security
FEATURE COMPARISON

Multi-Domain Wildcard vs. Wildcard vs. Multi-Domain SAN

Compare primary domain count, subdomain coverage, validation levels, and capacity.

WILDCARD SSL

Wildcard SSL

Best for one website with many subdomains. Covers 1 base domain + unlimited first-level subdomains. Available in DV and OV.

• Primary Domains: 1 domain only • Subdomains: Unlimited (1st level) • Validation: DV, OV (EV prohibited) • Starting Price: From $56.33/yr
MULTI-DOMAIN SAN

Multi-Domain (SAN) SSL

Best for several separate websites with no subdomain structure. Lists distinct primary domains up to 250 SANs. Available in DV, OV, and EV.

• Primary Domains: Multiple distinct domains • Subdomains: No (requires separate SAN) • Validation: DV, OV, EV • Starting Price: From $21.66/yr
HYBRID MD WILDCARD

Multi-Domain Wildcard SSL

Best for portfolios with several websites AND subdomains under each. Ultimate consolidation for agencies, SaaS, and multi-brand enterprises.

• Primary Domains: Multiple distinct domains • Subdomains: Unlimited per domain • Validation: DV, OV (EV prohibited) • Starting Price: From $150/yr
VALIDATION RULES

Validation Levels: DV and OV (and Why EV Is Not Available)

CA/Browser Forum Baseline Requirements strictly prohibit wildcard SAN entries on EV certificates.

FAST ISSUANCE

Domain Validation (DV)

Verifies that the applicant controls the listed domains via DNS record, email, or HTTP check. Issued in minutes. Ideal for SaaS platforms, staging, and internal corporate tools where speed matters.

• Issues in ~5 minutes • Automated DNS CNAME / TXT validation • Starting from $150/yr • Best for: Dev/test, staging, SaaS platforms
BUSINESS VETTING

Organization Validation (OV)

Verifies requesting business through official records: corporate registration, physical address, and telephone callback. Verified company name appears in certificate details. (Note: EV is globally prohibited on wildcards; OV is the highest level allowed).

• Issues in 1–2 business days • Verified business entity in certificate • Highest level available on wildcards • Best for: E-commerce, multi-brand companies
DEPLOYMENT USE CASES

Who Needs a Multi-Domain Wildcard Certificate?

Consolidate sprawling domain networks into a single manageable certificate lifecycle.

Multi-Brand Portfolios

Own brandA.com, *.brandA.com, brandB.net, and *.brandB.net? Replace four or more separate certificates with one consolidated issuance.

SaaS Tenant Subdomains

Provide customer1.app.com and customer2.app.com with wildcard coverage while securing marketing, docs, and API on other domains.

Hosting & Agencies

Managing client domains across many brands served from shared clusters fits this product cleanly: one certificate, one renewal cycle, one key.

Exchange & UCC Systems

Functions as a Unified Communications Certificate (UCC), satisfying Microsoft Exchange autodiscover, mail, and webmail requirements.

AUTHORITY LINEUP

Multi-Domain Wildcard Certificates We Carry

Compare enterprise offerings from Sectigo, GoGetSSL, GeoTrust, and Thawte.

SECTIGO

Sectigo PositiveSSL Multi-Domain Wildcard

Default packaging covers 4 SANs and scales up to 250 at checkout. Free site seal, unlimited reissues, and unlimited server licensing ship in the box. Trusted root chaining across 99.9% of global browsers.

• 4 SANs included by default • Expands up to 250 SAN entries • Unlimited server licenses & reissues • 256-bit AES / 2048-bit RSA or ECC
GOGETSSL

GoGetSSL Multi-Domain Wildcard SSL

Lowest price point in this category, covering 3 SANs by default with expansion to 250. Site seal, free reissues, and full server licensing included. Ideal entry point for developers needing fast domain control.

• 3 SANs included by default • Expands up to 250 SAN entries • Lowest price point in the market • Automated DNS issuance in 5 minutes
TECHNICAL CHECKLIST

Things to Know Before You Buy

Important operational considerations regarding public SAN visibility and reissuance.

VISIBILITY

Public SAN Transparency

All listed domains are publicly visible in the certificate details. If you don't want two competitor brands associated, use separate certificates.

• SAN list is public in certificate • Anyone inspecting cert sees all SANs • Separate certs for confidential brands • CT log monitoring transparency
BARE DOMAIN

Wildcard Doesn't Cover Bare Root

A SAN entry of *.domain.com covers mail.domain.com and shop.domain.com, but does NOT cover bare domain.com. Add the bare domain as its own SAN.

• *.domain.com covers subdomains only • Add domain.com explicitly as SAN • Pairing is seamless at checkout • Supported on all CA products
LIFECYCLE

Free Reissues & Expiration

Adding or removing SANs mid-cycle is free and unlimited. The new certificate inherits the original expiration date without resetting the clock.

• Unlimited free reissuances • Expiration date carries over • Fast domain control re-check • OV vetting reusable within validity
FAQ

Frequently Asked Questions

Common questions about this SSL certificate type and deployment.

Most products on this page support up to 250 total SANs (1 primary domain + 249 additional). Default packages start at 3 or 4 SANs included; you add more individually at checkout. A few Sectigo OV multi-domain wildcards support higher caps; check the specific product page for the exact ceiling.

Yes, free and unlimited via reissue. The expiration date stays the same; reissuing does not extend validity. For DV, you only need to prove control of any newly added domains; for OV, organization validation can usually be reused within the certificate’s lifetime, so reissues complete faster after the first one.

Functionally none, in most cases. UCC (Unified Communications Certificate) is the older naming used in Microsoft Exchange and Communications Server contexts. A multi-domain wildcard works as a UCC and supports the same FQDN flexibility Exchange requires for its autodiscover, mail, and webmail hostnames.

The CA/Browser Forum’s Baseline Requirements prohibit wildcard SAN entries on Extended Validation certificates. This is industry-wide, not a Renewal SSL limitation. Buyers who need EV identity on one specific hostname typically run two certificates side by side — an EV single-domain on the flagship hostname, and the multi-domain wildcard on the rest of the portfolio.

Yes. Every product on this page includes unlimited server licensing. Note that ‘unlimited’ refers to the right to install, not to security best practice. Distributing the same private key across many servers increases blast radius if any one server is compromised. Use private key rotation policies appropriate to your deployment scale.

Existing certificates remain valid until their issued expiration date. New certificates issued after each phase deadline must comply with the new ceiling: 200 days now, 100 days from March 2027, 47 days from March 2029. At 47 days, automation becomes a practical requirement.

Use our free CSR Generator tool or generate it on your server with OpenSSL. The Common Name (CN) must be a non-wildcard domain; list any wildcard entries (*.domain.com) in the SAN field instead, never in the CN.

0