Automatic TLS for custom domains
April 10, 2026. Custom domains get HTTPS automatically. No certificate purchase, no renewal calendar, no DNS scripting. Point your domain at SGEN, the certificate provisions, the site is HTTPS within minutes.
What changed
Before today, putting a custom domain on SGEN meant either accepting HTTP (no — modern browsers flag it as insecure) or wrestling with certificate provisioning yourself.
After today, every custom domain you point at a SGEN site gets:
- A valid TLS certificate, automatically issued
- HTTPS as the default protocol on every public page
- HTTP-to-HTTPS redirect automatically configured
- Automatic renewal before the certificate expires — no manual intervention
- The green padlock visitors expect on every modern site
How it works
The setup flow:
- Buy your domain from any registrar (we don't sell domains — pick whichever provider you prefer)
- In SGEN: Site → Settings → Domain, enter your domain
- SGEN shows you the DNS records to set at your registrar
- Set the records at your registrar (an A record + a CNAME, typically)
- Wait — the platform polls DNS until propagation completes
- Certificate provisions, HTTPS becomes the default
What it covers
- The apex domain (`yoursite.example`)
- The `www` subdomain (`www.yoursite.example`)
- Any subdomain you configure (`shop.yoursite.example`, `blog.yoursite.example`)
Why this matters
For a marketing site, HTTPS is now table stakes — without it, browsers show warnings, search engines de-rank, and visitors leave. Hand-rolling certificates was the gap between "I bought a domain" and "my site is public-ready."
That gap is closed. The certificate work disappears from your responsibility. You buy the domain, point it, the platform handles the rest.
For platforms competing against SGEN, free TLS isn't a differentiator — it's expected. The differentiator is the absence of friction. SGEN's setup flow doesn't ask you to think about certificates, because you don't need to.
Common patterns
- A team launching a new site. Buy `yoursite.example` Monday. Point at SGEN Tuesday morning. By Tuesday afternoon, the public site is at `https://yoursite.example` with a valid certificate. Wednesday they start writing content.
- An agency migrating a client from WordPress. The client's existing certificate (paid-for, manually renewed) becomes irrelevant. Point the domain at SGEN. Certificate provisions. The client's previous certificate renewal calendar can be retired.
- A multi-domain operator. Point `yoursite.example`, `yoursite.co.uk`, and `yoursite.de` at the same SGEN site. Each gets its own certificate. The operator manages zero of them.
What's not included
A few things you still own:
- Domain registration. You buy the domain from a registrar; we don't sell domains.
- DNS records. You set the records at your registrar; we tell you what records to set.
- Branded email (you@yoursite.example). Email DNS records (MX, SPF, DKIM) are separate from the web-domain DNS records SGEN manages. Set those at your registrar or with your email provider.
Next steps
- If you're setting up a new domain, go to Site → Settings → Domain and walk the flow.
- If you already pointed a domain, the certificate is already there — check the public URL.
- If you manage multiple sites, repeat the flow per site. Each domain on each site gets its own certificate.
