Automatically. You don't need to buy or renew a certificate.
Every custom domain you connect to Ambit gets a valid SSL certificate. That's the certificate that gives your URL the padlock icon in the browser and lets it serve over https:// instead of http://. We provision it for you, and we keep it renewed.
What happens behind the scenes
When you finish connecting your custom domain, Ambit requests an SSL certificate for it. The certificate is issued, installed, and active — usually within a few minutes of the DNS records resolving.
Once it's active, your funnel is served over HTTPS automatically. Visitors who type http://yourcompany.com are redirected to the secure version, so every visitor lands on a secure connection no matter how they reach you.
Renewals
SSL certificates expire on a schedule. Ambit renews yours automatically before they do. You don't have to track renewal dates, and your funnel won't go down because of an expired certificate.
When SSL doesn't activate
In rare cases, SSL won't activate on the first try — usually because of a DNS misconfiguration that's also blocking the domain from connecting. Two things to check:
The DNS record is set correctly. SSL relies on the same DNS settings the domain itself does.
CAA records aren't blocking the certificate. If your registrar has CAA records configured (most don't), they may need to allow the certificate authority Ambit uses. Our support team can help you sort this out.
Where to go next
How do I add a custom domain?
What DNS records do I need to set?
