SSL certificates can be valid for at most 199 days. From 15 March 2027 the limit becomes 99 days. Read more →
Sectigo

Sectigo PositiveSSL Multi-Domain/UCC

DV Max 199 days

E-mail, URL or DNS validation for multiple DNS domains on this multi SAN certificate, that includes 3 DNS names in the base price.

Validation
Domain Validation
Type
Multi-domain (SAN)
Certificate Authority
Sectigo

SAN pricing

Type Price per SAN/yr
SAN Subdomain/SAN FQDN 2x free
SAN FQDN €39 €20
SAN Subdomain €39 €20
SAN Wildcard €227 €114
256-bit encryption Free reissuance Root compatibility Windows Root Store The root is included from 2023 With 1 Cross-Sign the root is included from 2010 Microsoft's root store. It updates automatically on every supported Windows version. For older clients to validate, the server has to send the cross certificate on top of the ordinary intermediate. On Windows Server, Server Authentication also has to be turned off for the new root on the server: otherwise Schannel builds the short chain to the new root and the cross certificate is never sent.Apple Root Store The root is included from 2025 With 1 Cross-Sign the root is included from 2010 Apple's root store in iOS and macOS. It follows the operating system version, so older devices never receive new roots. For older clients to validate, the server has to send the cross certificate on top of the ordinary intermediate. On Windows Server, Server Authentication also has to be turned off for the new root on the server: otherwise Schannel builds the short chain to the new root and the cross certificate is never sent.Android Root Store The root is included from 2025 With 1 Cross-Sign the root is included from 2010 Android's built-in root store. It follows the Android version, and older phones rarely receive new roots. For older clients to validate, the server has to send the cross certificate on top of the ordinary intermediate. On Windows Server, Server Authentication also has to be turned off for the new root on the server: otherwise Schannel builds the short chain to the new root and the cross certificate is never sent.Linux Root Store The root is included from 2024 With 1 Cross-Sign the root is included from 2010 The Mozilla NSS bundle, shipped by Debian, Ubuntu and RHEL as ca-certificates. For older clients to validate, the server has to send the cross certificate on top of the ordinary intermediate. On Windows Server, Server Authentication also has to be turned off for the new root on the server: otherwise Schannel builds the short chain to the new root and the cross certificate is never sent.Java Root Store The root is included from 2025 With 1 Cross-Sign the root is included from 2010 The Java cacerts file. It follows the Java update installed on the server. For older clients to validate, the server has to send the cross certificate on top of the ordinary intermediate. On Windows Server, Server Authentication also has to be turned off for the new root on the server: otherwise Schannel builds the short chain to the new root and the cross certificate is never sent.8.1of 10Requires 1 Cross-SignCovered by the root certificate itselfCovered through one cross-signed certificate Max 249 SAN

About Sectigo PositiveSSL Multi-Domain/UCC

Sectigo PositiveSSL Multi-Domain is different kind of SAN SSL certificate, because it is e-mail/URL/DNS validated but allows multiple different DNS domains, in the SAN list. It usually requires heavier organization validated products in order to mix DNS names from multiple domains.

Perfect hosting SSL certificate with multiple customers, where the hoster controls either an approver e-mail or DNS of the customer.

The product is great for projects/servers requiring multiple SAN names, from multiple domains, possibly with different owners or where speed of issuance is important and all domains have working e-mail ready. I.e. a hosted server containing DNS names belonging to multiple customers.

Sectigo PositiveSSL Multi-Domain is a cheap alternative to GlobalSign Organisation SAN or GeoTrust TBID SAN if a lot of different DNS domains are needed or many different domains that may not have the same owner, the certificate allows a total of 250 DNS names, including the primary name.

Email approval supports multiple different domains, i.e. mail.domain.com and mail.company2.net, in the same certificate. All domains, must be able to receive email on one of following addresses admin@, administrator@, hostmaster@, postmaster@, webmaster@. No other e-mail addresses will be allowed.

The certificate price includes primary DNS name and 2 additional DNS SAN names, extra names cost extra.

 

Note - Sectigo has changed root certificate the 2nd of June 2025.
All certificates issued from this date will be from the new root CA certificates and issued with SHA2-384 hashing algorithm.
For more information click here.

Reissue schedule

Certificates must be reissued before they expire within the order period. The timeline shows when each reissue is needed.

1 year

Order: 1 year
↓ 99-day cap
199d
99d
67d
Sept 2026
Issue and install
Apr 2027
Reissue and install
Jul 2027
Reissue and install
Sept 2027
Renew order
+ issue new cert.

from

€153€77 /year excl. VAT
Buy Sectigo PositiveSSL SAN Compare certificates
  • 14-day full refund
  • Free phone support
  • No hidden fees
  • Unlimited server installation

Ready to create a free account?

Create a free account and order your first certificate. A DV certificate is issued in under 2 minutes.