Multi-Domain (SAN) SSL: Protect Multiple Domains with One Certificate
· Guide
Multi-Domain SSL certificates use the Subject Alternative Name (SAN) extension to list multiple different domain names within a single certificate — ideal for businesses managing multiple brands, products, or regional domains.
What Is SAN?
SAN (Subject Alternative Name) is an extension defined in the X.509 certificate standard. Certificates used to rely on a single Common Name (CN) field, but since 2017 — starting with Chrome and then spreading to every browser — browsers no longer check the CN, they check the SAN list. The CN field still exists for backward compatibility, but the actual hostname match happens against SAN. That's why a modern certificate's CN domain is usually added to its own SAN list automatically.
The Key Difference from Wildcard
SAN entries don't have to be subdomains of the primary domain — they can be completely unrelated domains:
- Wildcard (*.example.com): only covers first-level subdomains of example.com (like mail.example.com, shop.example.com).
- SAN: covers an exact, explicit list of domains — example.com can sit alongside a totally different domain like example.net or partner-brand.com on the same certificate.
A Concrete Example
Say a company configures a Multi-Domain SSL package like this:
- Primary domain (CN): example.com
- Additional SAN domains: www.example.com, mail.example.com, example.net, partner-brand.com
Result: one certificate file, one private key, but the certificate's SAN list covers all 5 domains: example.com, www.example.com, mail.example.com, example.net, partner-brand.com. Every one of them loads with a valid padlock in the browser — they all present the same certificate.
Why Each Domain Is Validated Separately
Since example.net and partner-brand.com are entirely different domains (different DNS zones, possibly different owners), the certificate authority requires separate proof of ownership for each one — proving you own example.com does not prove you own example.net. That's why, at order time, each SAN domain gets its own DNS record, its own HTTP validation file, or its own approval email — all can be completed in parallel, but none of them automatically validates another.
How Many Domains Can Be Added?
Standard SAN certificates typically support 3–100 domain entries. PekiSSL certificates are configurable with flexible SAN limits based on your needs; the base package price usually covers the primary domain, and each additional SAN domain is billed separately.
Who Benefits?
- E-commerce sites managing country-specific domains (site.com, site.de, site.fr)
- Hosting companies serving multiple client sites from one server
- Holding companies running separate brands as separate domains
- SaaS platforms with multiple TLDs (app.io, app.com, app.co.uk)
Management Advantage
One certificate = one renewal date = one management point. Instead of tracking dozens of certificates separately, you get a centralized setup. Note that if revocation is needed, the entire certificate is revoked — not individual SAN entries — so plan your risk management accordingly.
SAN vs Wildcard
| Feature | Wildcard (*.example.com) | SAN / Multi-Domain |
|---|---|---|
| Scope | All first-level subdomains of one domain | An exact, explicit list of domains |
| Adding an unrelated domain (e.g. example.net) | Not covered | Can be included |
| Spinning up a new subdomain | Automatically covered, no extra step | Must be added to the cert and re-validated |
| Validation | One-time, primary domain only | Separately, per domain |
| Typical use case | One brand, many unpredictable subdomains | Several fixed domains/brands |
| Pricing | Usually flat, independent of subdomain count | Primary domain + fee per additional SAN |
Visit the PekiSSL product page to find the right certificate for your needs.