Small job

SSL certificate, HTTPS and DNS setup for a WordPress website

We install or renew your certificate, send all traffic to HTTPS with one 301 redirect, fix mixed-content warnings and tidy your domain DNS so the site and e-mail keep working.

  • Typical scope approx. 2 h
  • Roughly 100 € + VAT
  • Assessment and estimate are free

The browser shows a “Not secure” warning on your website, the certificate has expired, or e-mail stopped arriving after the site moved to a new server. These are problems of the same layer: the WordPress SSL certificate, the HTTPS redirects and the domain’s DNS records. When one of them is wrong, visitors lose trust, Google indexes the site twice and messages go missing.

When the work is done, your site opens from every address (http, https, with and without www) via one 301 redirect to the final HTTPS address, the browser shows the padlock without warnings, the certificate renews itself and the domain’s DNS records are documented and consistent for both the website and e-mail.

What the work includes

  • Certificate installation or renewal. In most cases the free Let’s Encrypt certificate offered by your host is enough; we set it up and make sure it renews automatically. If you have a purchased certificate or need a wildcard certificate for subdomains, we install it together with the intermediate chain so that no browser or mobile app complains.
  • Forcing HTTPS with 301 redirects. We configure redirects at server level (.htaccess or Nginx) so that http and https, www and non-www all lead in a single hop to one canonical address. No redirect chains are left behind.
  • Updating the WordPress address. We switch the WordPress and site address settings to https and replace old http:// references in the database (posts, menus, widgets, theme settings) with a search-and-replace that keeps serialised data intact.
  • Fixing mixed content. We find the http:// images, scripts and fonts in the theme, plugins and content that stop the browser from showing the padlock and fix them at the source rather than just masking them with a plugin.
  • HSTS and security headers. Once the site runs reliably on HTTPS, we add an HSTS header with a sensible max-age and review the other security headers. We submit to the HSTS preload list only when every subdomain is ready for it.
  • Tidying the DNS records. We review the A/AAAA, CNAME, MX, SPF, DKIM and DMARC records and the verification TXT records (Google Search Console, Microsoft 365, Google Workspace), remove stale entries and document what points where.
  • Moving the domain without downtime. When moving to a new host or registrar we lower the TTL first, switch DNS in a controlled order and keep the MX records for e-mail working. If you want, we move DNS to Cloudflare and set up the proxy with the right SSL mode.
  • Checking automatic renewal. We make sure the certificate renews on its own and that the ACME challenge passes behind the redirects or the Cloudflare proxy, so nobody has to do it by hand in a couple of months.
  • Testing. We check the result with the SSL Labs test, in different browsers and on mobile, walk through every redirect and review Search Console so that Google sees only one address.

Typical situations

The browser shows “Not secure” because the host’s free certificate expired and automatic renewal failed silently. A certificate is installed but there is no padlock, because the theme loads fonts and images from an http:// address. The site was moved to a new server and the A record was changed, but the MX records stayed on the old host’s nameservers and business e-mail stopped. Google indexes both the www and the non-www version and Search Console reports duplicate content. The domain is registered in one person’s name, the nameservers are at another host and nobody knows exactly where which setting is changed.

What we need from you

  • Access to the hosting control panel (cPanel or Plesk, for example) or to the server over SSH.
  • Access to the domain registrar or DNS management, or a person who applies the changes following our instructions.
  • A WordPress administrator account.
  • For a purchased certificate, the certificate files and private key, or the right to order them.
  • A list of services that use the domain: e-mail, newsletter tool, CRM, subdomains.
  • A decision on the canonical address: with or without www.

What is not included

  • Moving the site’s files and database to a new server is a separate server migration service; we do handle the DNS switch as part of it.
  • Setting up WordPress e-mail sending over SMTP and monitoring DMARC reports is the e-mail deliverability service. Tidying the SPF, DKIM and DMARC records in DNS is done here.
  • Hosting and domain fees and the price of a purchased certificate.
  • Malware removal, when the warning is actually caused by an infected site.
  • Checking the SEO impact of URL changes, when addresses change by more than just the protocol, is the SEO migration check.

Who it suits

It suits any owner of a WordPress or WooCommerce site whose browser shows a warning, whose certificate has expired or who is changing host or domain. If you want someone to look after the certificate, backups and updates on an ongoing basis, see the hosting and maintenance service. If you want a review of the whole site’s security rather than just the certificate, start with a website health and security audit.

approx. 2 h Typical scope
50 € Hourly rate + VAT
100 € Estimated total

This is an estimate, not a quote. We’ll review your site free of charge first and tell you the exact time required. If the job turns out smaller, you pay less – we bill for the time actually spent.

How this job works

  1. Send an enquiry

    Send us your site address and a couple of sentences about the problem. We usually reply the same or the next working day.

  2. We review it and give you the price

    The assessment is free. You’ll know the exact time and price before you decide on anything.

  3. We do the work and report back

    We take a backup before making changes. When the work is done you get a summary of exactly what was done and what to keep an eye on going forward.

Frequently asked questions

Is the free Let's Encrypt certificate enough, or should I buy one?

For most websites and online shops Let's Encrypt is enough; the encryption is just as strong. A purchased certificate makes sense when you need organisation validation, a wildcard certificate your host does not support, or when the host does not offer Let's Encrypt at all.

Why does the browser still warn me even though a certificate is installed?

Usually it is mixed content: the page loads images, scripts or fonts from an http:// address. Less often the intermediate chain is missing or a redirect leaves part of the site on http. We find both during diagnosis and fix them.

Will changing DNS take the site or e-mail offline?

Not when done in the right order. We lower the TTL first, change the records once the new server is ready and leave the MX records untouched if e-mail is not moving. During the short propagation window the site works in both places.

Do I have to renew the certificate by hand in the future?

No. A Let's Encrypt certificate is short-lived and renews automatically. We check that the renewal process really works and recommend setting up an expiry alert so that a problem never comes as a surprise.

What does it cost and how quickly is it done?

We start with a free review and estimate and bill by the actual time spent. Certificate and redirect setup is usually finished the same or the next working day after we receive access; DNS propagation adds a few hours.

Testimonials

What our clients say

Long-standing partnerships say more than any slogan. Several of the clients below have been with us for over seven years.

We have worked with Birk for eight years now. This time we wanted a new website for the company, and the goals were set high from the very start – in visuals, functionality, manageability and SEO. Thanks to Birk’s professional approach we got a website of a high standard that met our expectations 100%. The collaboration went smoothly because Birk is a very good and direct communicator, helpful, dependable and conscientious.
Karina Riive Karina Riive LIGNAMETS OÜ, FARMLAND PURCHASING MANAGER
We ordered a feature-rich bespoke online store from Zezz. It was also important that it integrate with our accounting software. Zezz handled the task well and has been our day-to-day web development partner since 2018. Overall score 8/10 – there is always room to do better.
Aivo Kuldmeri Aivo Kuldmeri WESTBERG KAUBANDUS, MANAGING DIRECTOR
As a client you sometimes feel that you don’t know exactly how, and sometimes not even exactly what. But our collaboration has produced a website that our own people value and others try to copy. Thank you for the patience, the good ideas and the understanding. Thank you for visualising it and making it visible. I liked that Zezz keeps its word and stays flexible.
Mart Tilk Mart Tilk MANAGER, MÄRJAMAA SPORTS CENTRE

See our clients and testimonials

Get in touch

Let’s talk about your project

The first hour of consultation is free and comes with no obligation. We usually reply the same or the next working day.

  • The first hour is free – even if we don’t end up working together
  • You get a concrete price and timeline, not a vague “about”
  • No sales pressure and no automated follow-up calls

Request a quote

Describe what you need in a couple of sentences. We’ll get in touch and arrange a free consultation.


    Your details are never shared with third parties or used for newsletters.