How to Get a Free SSL Certificate with PekiSSL (2026 Guide)
· Guide
PekiSSL provides completely free SSL/TLS certificates using the Let's Encrypt infrastructure. As of 2026, the new CNAME delegation architecture means no Cloudflare API token is required — it works with any DNS provider.
What Is Let's Encrypt?
Let's Encrypt is a non-profit Certificate Authority (CA) operated by the Internet Security Research Group (ISRG). Because its root certificate is trusted by browsers and operating systems, you won't see "This certificate is not trusted" warnings. Certificates are valid for 90 days, so you need a new certificate before they expire.
PekiSSL's New Architecture: CNAME Delegation
PekiSSL now performs DNS-01 validation using CNAME delegation. Here's what that means:
Before: You had to move your domain's DNS to Cloudflare and enter an API token. PekiSSL used that token to write and delete validation TXT records on your behalf.
Now: You add a single CNAME record to your DNS provider (Cloudflare, GoDaddy, Namecheap, Route53 — all work). This record is added once and never needs to be touched again. After that, PekiSSL writes validation TXT records to its own zone (acme.pekissl.com) — no access to your DNS is required.
Example CNAME record (for example.com):
Type: CNAME
Host: _acme-challenge
Value: example-com.<your account code>.acme.pekissl.com (the Checkout page shows your exact value)
TTL: 300
The same record works for wildcard certificates (*.example.com) too. Add it once and it will be reused for every renewal and future certificate request.
Prerequisites
- You must own a domain name.
- You need access to your DNS provider to add a CNAME record (any DNS provider works).
- You must have created a PekiSSL account and be logged in.
- No Cloudflare API token or specific DNS provider is required.
Step 1 — Create an Order on PekiSSL
Log in to your account at PekiSSL.com. Select the "Free SSL" package from the Pricing page and click "Get Started." On the Checkout page, fill in the following:
Domain Name: Enter the domain you want the SSL certificate for. For a single domain, e.g. example.com; for wildcard, enter *.example.com.
Include Apex Domain: When getting a wildcard certificate, checking this option covers both *.example.com and example.com under a single certificate.
Fill in contact information such as Full Name, Email, and Country.
The required CNAME record is automatically displayed on the checkout page just below the domain input.
Step 2 — Add the CNAME Record to Your DNS Provider
Copy the CNAME value shown on the Checkout page and create the following record in your DNS provider's management panel:
Type: CNAME
Host / Name: _acme-challenge (some providers require _acme-challenge.example.com)
Value / Target: example-com.<your account code>.acme.pekissl.com
TTL: 300
The interface varies by DNS provider, but the record types are the same. You can click "Verify DNS" on the Checkout page to confirm the record has propagated.
You only need to add this record once. Future renewals and new certificate requests for the same domain do not require you to add it again.
Step 3 — Submit the Order
After adding the CNAME record, click "Get Free Certificate." When the order is created:
- The system automatically initiates the ACME validation process in the background.
- Thanks to the new async architecture, the checkout screen closes within 2-3 seconds.
- Your certificate will be ready within 2-5 minutes.
- Once ready, it appears on your "My Certificates" page.
Step 4 — Download Your Certificate
After the order is completed, navigate to "My Certificates" from the left menu. Find the generated certificate and click the "Download" button. The downloaded files will include:
certificate.crt — The SSL certificate to install on your server
private.key — Your private key (keep this secret, do not share!)
ca-bundle.crt — The intermediate CA certificate chain (required for some servers)
Server Installation
For Nginx, add the following to your configuration file:
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /etc/ssl/certs/certificate.crt;
ssl_certificate_key /etc/ssl/private/private.key;
ssl_trusted_certificate /etc/ssl/certs/ca-bundle.crt;
}
For Apache, add the following:
SSLEngine on
SSLCertificateFile /etc/ssl/certs/certificate.crt
SSLCertificateKeyFile /etc/ssl/private/private.key
SSLCertificateChainFile /etc/ssl/certs/ca-bundle.crt
For cPanel users: Go to cPanel > SSL/TLS > "Manage SSL Sites" and copy-paste the relevant fields.
Frequently Asked Questions
Is Cloudflare no longer required? Correct. Thanks to the CNAME delegation architecture, any DNS provider works (GoDaddy, Namecheap, Route53, Google Domains, etc.). You do not need to switch to Cloudflare.
Do I add the CNAME record only once? Yes. Once added, the record is reused for renewals and new certificate requests. PekiSSL writes TXT validation records to its own zone, not yours.
Can I get a wildcard certificate? Yes. Enter *.example.com in the domain field on the Checkout page. With the "Include apex domain" option, you can get a single certificate covering both *.example.com and example.com at once.
How long does it take for the certificate to be ready? Your certificate will be ready within 2-5 minutes of placing the order. As long as the CNAME record is correctly added, the process is fully automatic with no intervention required.
How many days is the certificate valid? Let's Encrypt certificates are valid for 90 days and are not renewed automatically. Before expiry, place a new free order for the same domain on PekiSSL; as long as your CNAME record is in place you don't need to touch your DNS, and the certificate is ready in a few minutes. Remember to install the new certificate on your server.
What if the CNAME record hasn't propagated? The "Verify DNS" button on the Checkout page checks in real time whether the record has propagated. After adding the record, propagation usually takes 1-5 minutes. If it still hasn't propagated after a long time, try clearing your DNS provider's cache or experiment with a different TTL value.
Visit the PekiSSL Pricing page to get your free SSL certificate.