SSL/TLS glossary

What is Let's Encrypt?

Let's Encrypt is a certificate authority that issues TLS certificates for free, automatically, to anyone who can prove control of a domain. It is run by the Internet Security Research Group, a nonprofit, and it launched to the public in 2015 with the goal of making HTTPS the default for the whole web. It became the largest certificate authority by volume, issuing millions of certificates a day.

What makes it different from older authorities is automation. Instead of a manual purchase, you run an ACME client such as certbot, which proves domain control by answering a challenge, receives the certificate, and renews it on a schedule without anyone involved. That model is why free issuance is sustainable: there is no human in the loop, so there is nothing to charge for.

The trade-off people notice first is the lifetime. Let's Encrypt certificates last 90 days, far shorter than the year-plus lifetimes that commercial authorities long offered. The short life is deliberate — it forces automation and limits the damage of a leaked key — but it means renewal has to work reliably, because a stalled renewal turns into an expired certificate within weeks. Let's Encrypt has also announced even shorter options, including a six-day profile, and plans to shorten the default further.

Two operational notes matter. Let's Encrypt issues domain-validated certificates only, so if a policy requires organisation or extended validation, it is not the right authority. And it enforces rate limits to protect the service, which a runaway renewal loop can hit. For most sites, though, it is the straightforward path to free, automated HTTPS, and its certificates are trusted in every mainstream browser without any extra step.

Source: Let's Encrypt: how it works

Common questions

Are Let's Encrypt certificates as trusted as paid ones?

Yes. They chain to roots in every major trust store, so browsers treat them identically to certificates from paid authorities. The connection security is the same; only the validation type and lifetime differ.

Why do Let's Encrypt certificates expire so quickly?

The 90-day lifetime forces automated renewal and limits how long a compromised key stays useful. It is safe as long as renewal is automated and monitored, so a failure surfaces before the certificate lapses.

Reading up because something broke? Check the certificate you actually serve — 3 monitored free, no card.

One check now, or every day from now on.

3 certificates free forever · No agent · No credit card