Multi-Domain (SAN) SSL: Protect Multiple Domains with One Certificate

· Guide

Multi-Domain SSL certificates use the Subject Alternative Name (SAN) extension to list multiple different domain names within a single certificate — ideal for businesses managing multiple brands, products, or regional domains.

What Is SAN?

SAN (Subject Alternative Name) is an extension defined in the X.509 certificate standard. Certificates used to rely on a single Common Name (CN) field, but since 2017 — starting with Chrome and then spreading to every browser — browsers no longer check the CN, they check the SAN list. The CN field still exists for backward compatibility, but the actual hostname match happens against SAN. That's why a modern certificate's CN domain is usually added to its own SAN list automatically.

The Key Difference from Wildcard

SAN entries don't have to be subdomains of the primary domain — they can be completely unrelated domains:

A Concrete Example

Say a company configures a Multi-Domain SSL package like this:

Result: one certificate file, one private key, but the certificate's SAN list covers all 5 domains: example.com, www.example.com, mail.example.com, example.net, partner-brand.com. Every one of them loads with a valid padlock in the browser — they all present the same certificate.

Why Each Domain Is Validated Separately

Since example.net and partner-brand.com are entirely different domains (different DNS zones, possibly different owners), the certificate authority requires separate proof of ownership for each one — proving you own example.com does not prove you own example.net. That's why, at order time, each SAN domain gets its own DNS record, its own HTTP validation file, or its own approval email — all can be completed in parallel, but none of them automatically validates another.

How Many Domains Can Be Added?

Standard SAN certificates typically support 3–100 domain entries. PekiSSL certificates are configurable with flexible SAN limits based on your needs; the base package price usually covers the primary domain, and each additional SAN domain is billed separately.

Who Benefits?

Management Advantage

One certificate = one renewal date = one management point. Instead of tracking dozens of certificates separately, you get a centralized setup. Note that if revocation is needed, the entire certificate is revoked — not individual SAN entries — so plan your risk management accordingly.

SAN vs Wildcard

| Feature | Wildcard (*.example.com) | SAN / Multi-Domain |
|---|---|---|
| Scope | All first-level subdomains of one domain | An exact, explicit list of domains |
| Adding an unrelated domain (e.g. example.net) | Not covered | Can be included |
| Spinning up a new subdomain | Automatically covered, no extra step | Must be added to the cert and re-validated |
| Validation | One-time, primary domain only | Separately, per domain |
| Typical use case | One brand, many unpredictable subdomains | Several fixed domains/brands |
| Pricing | Usually flat, independent of subdomain count | Primary domain + fee per additional SAN |

Visit the PekiSSL product page to find the right certificate for your needs.

All blog posts