Wildcard SSL without buying a retail CA SKU
Business unlocks *.example.com Let's Encrypt wildcards via DNS-01. docstoc manages the ACME order — we are an automation layer, not a certificate reseller.
Cover every first-level subdomain with one cert
A wildcard like *.example.com secures app.example.com, staging.example.com, and other first-level names under that parent — without issuing a separate cert for each. The apex (example.com) is a separate name unless you add it as a SAN.
- Business plan only
- Let's Encrypt DV wildcard via DNS-01
- Download PEMs and install where TLS terminates
- Same renewals flow as single-name certs
Vs ZeroSSL Premium–style pricing
Dedicated SSL dashboards often gate wildcards behind a Premium tier (~$55–$70/mo range historically). docstoc Business bundles wildcards with the rest of the workspace at Business pricing — still LE as the CA, still automation not resale.
- No separate “buy a wildcard” checkout
- Competes on automation + plan value, not CA brand shopping
- Stay on a commercial CA if you need OV/EV wildcards or warranties
Risks to understand
One private key covers many hostnames. Treat key storage carefully; prefer per-host certs when blast radius matters more than convenience.
- Key compromise affects every name under the wildcard
- Does not cover nested names like a.b.example.com
- Not more “secure” than a single-name cert — only more convenient
- Free — 5 × 90-day single-name LE certs
- Pro — multi-SAN + higher slot count
- Business — wildcards + volume (up to 25 cert slots)
Try it
Tools for a quick check — or open the product when you’re ready to issue.
Upgrade to Business → · Coming from ZeroSSL?FAQ
Which plan includes wildcards?
Business. Free and Pro issue single-name (and Pro multi-SAN) certificates; Business unlocks *.example.com wildcards plus higher volume.
Is this a sold wildcard SKU from a commercial CA?
No. docstoc is an automation layer. The certificate is a Let's Encrypt DV wildcard. You pay for managed ACME and workspace features — not a marked-up retail wildcard product.
Why DNS-01 for wildcards?
Let's Encrypt requires DNS-01 for wildcards. docstoc shows the TXT challenge(s) to publish; HTTP file validation cannot issue *.example.com.