Multi-domain (SAN) certificates: one certificate for multiple domains

A multi-domain TLS certificate is a single X.509 certificate whose Subject Alternative Name (SAN) extension contains multiple identities the certificate can represent. For public TLS certificates, those identities are usually DNS hostnames such as www.yourdomain.com, api.yourdomain.com, and shop.yourdomain.net.

Multi-domain SAN certificates

A client accepts the certificate for a connection only when the requested server name matches an appropriate identity in the certificate, and the rest of the certificate validation process succeeds.

DigiCert markets multi-domain certificates as SAN certificates and currently supports configurations with up to 250 domain names, depending on the selected product, account configuration, pricing, and applicable certificate-policy constraints.

Note: SAN is a certificate name-binding mechanism. It is not the same thing as SNI, and it does not inherently require every hostname to share one server, one IP address, or one deployment target.

When does a SAN certificate make sense?

A SAN certificate is useful when multiple known identities should intentionally share one certificate lifecycle. Common examples include:

Do not choose a SAN certificate solely to reduce certificate count. The larger the name set and the broader the certificate/key distribution, the larger the potential blast radius of expiration, revocation, deployment error, or private-key compromise. Sometimes several smaller certificates are the safer operational design.

SAN, wildcard, and separate certificates solve different problems

How hostname matching works

Modern TLS clients compare the server name they are connecting to with identities in the certificate, primarily the SAN extension. A SAN certificate covers only the identities actually encoded in the certificate, subject to normal hostname-matching rules.

How domain control validation works for SAN certificates

Before a publicly trusted TLS certificate is issued, the CA must establish authorization or control for every requested DNS identity under the CA/Browser Forum Baseline Requirements. That does not necessarily mean one completely separate manual validation transaction for every SAN.

In DigiCert CertCentral, the validation behavior depends on certificate type, DCV method, validation scope, and whether a qualifying validation is already current:

Why SAN certificates are not the same as SNI

SAN certificates and SNI address different parts of HTTPS virtual hosting. A SAN certificate defines which names one certificate can represent, while SNI lets a server select the appropriate certificate for the hostname the client requests. Two common architectures are:

This distinction matters operationally. A SAN certificate consolidates names, while SNI allows certificate isolation without requiring a dedicated IP address per hostname on modern clients and servers.

Can you add SANs after issuance?

For current DigiCert multi-domain TLS products, SAN changes are performed through reissue. DigiCert supports reissues for multi-domain certificates, but adding SANs is not universally free. Additional SANs can create additional charges depending on the product, plan, and remaining coverage.

Security and operational considerations

Choosing SAN versus wildcard versus separate certificates

Where DigiCert fits

DigiCert supports multi-domain public TLS certificates and provides certificate-lifecycle capabilities for discovering, issuing, renewing, deploying, and governing certificates across supported environments. The right automation pattern depends on where TLS terminates and how certificates are stored and bound.

Supplemental resources

Frequently asked questions

What is a multi-domain SAN certificate?
A single TLS certificate containing multiple identities in the Subject Alternative Name extension. Those names can include hostnames under the same or different base domains, subject to product and policy constraints.
How many domains can a DigiCert multi-domain certificate include?
DigiCert currently markets multi-domain configurations with up to 250 domain names. Treat that as a current DigiCert product limit rather than an inherent X.509 or SAN protocol limit; account, product, pricing, and policy constraints can also apply.
Does every SAN require a separate validation?
The CA must have valid authorization/control for every requested DNS identity, but that does not always mean a separate manual DCV transaction for each SAN. DigiCert supports validation scopes and, for OV/EV certificates, reuse of current domain validation within the permitted period. Some DCV methods validate only the exact FQDN.
Can SAN certificates be EV certificates?
Yes, DigiCert supports EV multi-domain certificates. EV validation adds organization and verified-contact requirements in addition to domain control validation. EV does not make a SAN certificate technically stronger cryptography, and it changes the identity-validation level and certificate policy.
Do SAN certificates let multiple HTTPS sites share one IP address?
A single SAN certificate can cover several hostnames served from one IP, but SAN doesn't enable a server to choose among different certificates. SNI is the TLS extension modern clients and servers use to select the appropriate certificate for a hostname when several certificates share one IP address.
Is a SAN certificate safer than a wildcard certificate?
Not automatically. SANs give explicit name scope, while a wildcard covers a namespace pattern. Security also depends on private-key distribution, number of services sharing the certificate, ownership boundaries, deployment controls, and recovery design. A very large SAN certificate shared broadly can have a large blast radius too.
What happens if a large SAN certificate expires or is revoked?
Every endpoint relying on that specific certificate can be affected at the same time. Other independently issued certificates for the same names are not automatically invalidated. This is why blast-radius analysis and verified automated renewal/deployment are important before consolidating many services onto one certificate.

Ready to evaluate your environment?

See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across protected web servers and the rest of your enterprise certificate estate.

Explore DigiCert Trust Lifecycle Manager Talk to DigiCert