Connect securely. Grow together.Automate your SSL workflows with the API
BUYING GUIDE

Wildcard vs Multi-Domain SSL: Which One Do You Need?

Wildcard and multi-domain SSL certificates solve different problems: one covers a growing set of subdomains, the other covers a fixed list of different domains. Here's what each actually covers, where they overlap, and how to pick the right one.

What a Wildcard SSL Certificate Covers

A wildcard SSL certificate secures one base domain plus every subdomain at a single level below it, using a certificate common name written as *.example.com. One certificate, installed correctly on each host, lets www.example.com, shop.example.com, and mail.example.com all present the same trusted certificate.

Most wildcard products also include the bare domain (example.com) as an additional name on the certificate, though this varies by product, so it's worth checking the wildcard SSL product details before you buy. Wildcards are the natural fit whenever the number of subdomains keeps growing and you don't want to request a new certificate every time someone spins one up — a common pattern for SaaS platforms that create a subdomain per customer.

What a Multi-Domain (SAN/UCC) SSL Certificate Covers

A multi-domain SSL certificate — also called a SAN certificate (Subject Alternative Name) or, in older Microsoft documentation, a UCC (Unified Communications Certificate) — covers several distinct hostnames in a single certificate, regardless of whether they share a domain. One certificate can list example.com, example.net, app.example.io, and a completely unrelated brand domain, all at once.

How many hostnames fit depends entirely on the product: some multi-domain SSL certificates ship with a handful of SAN slots included and let you add more, others cap out lower. Check the exact SAN allowance before assuming a single certificate will cover every domain you manage.

Wildcard vs Multi-Domain SSL: Side-by-Side Comparison

The table below lines up the two approaches on the points that usually decide the purchase.

AspectWildcard SSLMulti-Domain SSL (SAN/UCC)
What it coversOne base domain + unlimited subdomains at one level (*.example.com)A fixed number of specific hostnames, on any domains
Adding a new host laterAutomatic — any new subdomain at that level is already coveredRequires reissuing the certificate to add a SAN entry
Different domains / ccTLDsNot covered — one wildcard only spans one domainCovered — SANs can be any registered domain
Typical buyerSaaS platforms, apps with per-customer subdomainsAgencies, enterprises with several brands or ccTLDs
Validation levelsDV or OVDV, OV, or EV depending on product
Can combine bothYes — as SAN entries that are themselves wildcardsYes — see below

Typical Scenarios: Which Certificate Fits

Three situations come up constantly when resellers help customers choose between the two:

  • SaaS with many subdomains. A platform that provisions customer1.app.com, customer2.app.com, and so on for every new signup is the textbook wildcard case — one wildcard certificate keeps covering new customers without a reissue each time.
  • Agencies managing many client domains. A digital agency running ten unrelated client domains rarely needs a wildcard on any single one of them; a multi-domain certificate — or, more commonly for agencies, individual certificates per client billed through one reseller account — is the practical fit.
  • A company with several brands or country domains. An enterprise selling under brand.com, brand.co.uk, and brand.com.tr needs those exact hostnames on one certificate, which is precisely what a multi-domain/SAN certificate is built for.

Combining Both: Wildcard SAN Certificates

Some products let you combine the two approaches: a multi-domain certificate whose SAN entries are themselves wildcards, for example *.example.com and *.example.net in the same certificate. This "wildcard SAN" (or multi-domain wildcard) setup suits an agency or enterprise running several brands that each need their own growing set of subdomains, without buying a separate wildcard per brand.

Not every product line offers this combination, and the number of wildcard SAN slots is usually more limited than plain SAN slots, so confirm it's available on the specific multi-domain SSL product before assuming it will work for your case.

Limits to Know: Subdomain Levels and SAN Counts

Wildcards only reach one level down. *.example.com covers www.example.com and shop.example.com, but not a.b.example.com — that second-level host needs its own wildcard (*.b.example.com) or its own certificate entry. This trips people up more than anything else when they assume a single wildcard covers an entire domain tree.

On the multi-domain side, the limit is a hard SAN count set by the product, not the domain structure. Once you hit that count, you either move to a product with a larger SAN allowance or issue a second certificate — there is no "unlimited SAN" option. Compare the exact allowances on the pricing page before committing to a product for a domain list that's still growing.

Validation Levels and Security Considerations

Wildcard certificates are issued at domain validation (DV) or organization validation (OV) — there is no EV wildcard. If your certificate needs to show EV-level organization vetting, you'll be listing individual hostnames rather than a wildcard entry. Multi-domain certificates, by contrast, are available at DV, OV, or EV depending on the product, and each hostname you add still has to pass its own domain control validation (DNS, HTTP file, or email) before it's added to the certificate.

Security-wise, both approaches share one private key across every host the certificate covers. That's the whole point operationally, but it also means a key or server compromise on any one of those hosts puts every other covered host at risk of impersonation. Keep the private key restricted to the servers that need it, automate renewal, and treat wildcard and multi-domain keys with tighter access controls than a single-domain certificate would need. This matters more every year as maximum validity periods keep shrinking — down to 200 days from March 2026 under the CA/Browser Forum's current schedule — which makes automating reissuance across every covered host less optional than it used to be.

Cost Logic: One Certificate vs Several

The cost comparison isn't wildcard-vs-multi-domain in isolation — it's "one certificate that covers everything" versus "several single-domain certificates," and either wildcard or multi-domain can win that comparison depending on your domain layout. A wildcard replaces an unbounded number of subdomain certificates for one price; a multi-domain certificate replaces a handful of single-domain certificates for a price that scales with the SAN count.

Reseller pricing for both types is public, without signing up, on the pricing page linked above; at the time of writing (September 2026) the cheapest DV SSL on the Standart package starts at $1.99/year, and wildcard and multi-domain products sit above that baseline — check the pricing page for current numbers on the exact product you need. Packages also get cheaper automatically as issuance volume grows, from Standart up through Premium, Elite, and Ultimate, so a reseller selling either certificate type at scale pays less per certificate over time.

Decision Checklist: Which SSL Do You Need?

Run through these questions before choosing:

  • Will the number of subdomains under one domain keep growing without you controlling it in advance? Wildcard fits.
  • Do you need to cover several distinct domain names or ccTLDs on one certificate? Multi-domain (SAN/UCC) fits.
  • Do you need both — several brands, each with a growing set of subdomains? Check whether a wildcard SAN product is available.
  • Does the certificate need EV-level vetting? Neither a wildcard nor a wildcard-SAN certificate will work; use individual EV or multi-domain EV certificates instead.
  • Is the domain list fixed and small? Individual single-domain certificates may simply be cheaper and easier to manage.

Whichever direction fits, wildcard and multi-domain SSL certificates from Sectigo, GeoTrust, GlobalSign, Thawte, Certum, and sslTrus are available at reseller pricing through SSLCipher, with a free reseller account giving you access to both product lines, a panel for CSR generation and domain validation, and API access for automating issuance across every host you cover.

Frequently asked questions

01Can one certificate cover both a wildcard and multiple separate domains?

Yes, some multi-domain products support wildcard SAN entries, letting one certificate list *.example.com alongside *.example.net or other hostnames. Not every product line offers this combination, so confirm wildcard SAN support before assuming it fits your domain list.

02Does a wildcard SSL certificate cover subdomains of subdomains?

No. *.example.com covers one level down, such as shop.example.com, but not a deeper host like a.b.example.com. You would need a separate wildcard (*.b.example.com) or an individual certificate entry for that host.

03Can I get an EV wildcard SSL certificate?

No. Wildcard certificates are only issued at domain validation (DV) or organization validation (OV); there is no EV wildcard product, because EV vetting is tied to specific, individually verified hostnames rather than an open-ended pattern.

04Is a multi-domain SSL certificate the same as a UCC certificate?

Largely yes. UCC (Unified Communications Certificate) is an older name Microsoft used for SAN certificates built for Exchange and Office Communications Server. Today the terms multi-domain, SAN, and UCC certificate mostly describe the same underlying certificate type.

All articles
SSLCIPHER PARTNERSHIP

Take your next growth step
with confidence.

Manage your SSL processes from a single hub. Spend more time on your business and your customers.