নতুন সার্ভার থেকে চালু দোকান পর্যন্ত · ধাপ 4 / 8
Domains and HTTPS
What this page is for. Point your domain name at this server and get a free certificate, so visitors see the padlock instead of a warning.
You need
- A domain name you own.
- Access to that domain's DNS settings — or a Cloudflare API token connected to the panel, in which case the panel does the DNS part for you.
- The panel open on Domain & SSL (a Project page).
How this works, in four sentences
A domain name is a label. DNS is the phone book that turns that label into your server's IP address. Something has to add an A record pointing the name at this server — either you at your DNS provider, or the panel on your behalf when Cloudflare is connected. Once the name arrives here, SixPanel asks Let's Encrypt for a free certificate and turns on https.
Each name moves through three states, shown as chips on the page:
added → pointed → secured
- added — SixPanel knows about the name.
- pointed — the name really resolves to this server.
- secured — a certificate is installed and
httpsworks.
The three groups
The Domain & SSL page has one card per group. A group can hold more than one name.
| Card | What it is for |
|---|---|
| Admin site (main domain) | Your 6ammart admin panel, and the address the mobile apps talk to. The name marked primary is the main one. |
| Customer website | The storefront your customers browse. See The customer website. |
| Live updates (websockets) | An optional separate name for real-time order updates. See Live order updates. |
1. Add the name
In the right card, type the bare name — shop.example.com, with no https:// and no slash.
Before you press anything, the panel says where that domain lives. Type the name and wait a moment; one of three answers appears under the box:
- The Cloudflare account connected here manages it. Nothing more is asked. Adding the name creates the record and gets the certificate for you.
- It is not under the account connected here. You get two ways through — paste that account's own API token, or add the record yourself in whatever DNS you use, keeping it proxied, and press check again. The domains this panel's token can see are listed by name, so a typo in the name is easy to spot.
- It would sit too deep to be secured.
dash.shop.example.comunder the domainexample.comis two levels down, where Cloudflare's free certificate does not reach. The panel says so and offers the spelling that works (dash-shop.example.com) with a button that fills it in. It never silently rewrites what you typed.
Then press Add domain.
Expected result: the name appears with an added chip, and on a domain this panel manages it goes on to create the DNS record and get HTTPS by itself — each step shown as it finishes. If DNS already points here you get pointed straight away.
When you installed the project, the address you typed there became its admin panel address, and only that one. The website and websocket addresses are added here, whenever you want them — that is what this card is for.
2. Point it at this server
If Cloudflare is connected, you do not do this by hand. The panel creates the A records for you, and every record it creates is proxied — the orange cloud — so your server's address never appears in public DNS.
One rule follows from that, and the panel enforces it. Cloudflare's free certificate covers your domain and one level below it: example.com and shop.example.com, but not dash.shop.example.com. A proxied name that sits deeper answers every HTTPS connection with a handshake failure at Cloudflare's edge, before your server is even dialled. So the panel picks names that fit: a name that would sit deeper is flattened with a hyphen — dash-shop.example.com, ws-shop.example.com, panel-shop.example.com — and if you type a deeper name by hand the panel refuses it and shows you the spelling that works. There is no "turn the proxy off for this one" option, because a name with the proxy off publishes the address of your server.
If Cloudflare is not connected, the card shows This server's IP address (for the A records) with a copy button. Copy that number, and at your domain provider create a DNS A record:
| Field | What to enter |
|---|---|
| Type | A |
| Name / Host | the part before your domain (shop), or @ for the domain itself |
| Value / Points to | the IP address you copied |
| TTL | leave the default |
Then press Re-check on that row, or Re-check DNS at the top of the page.
Expected result: the chip turns to pointed.
The row that says "not pointed" carries the fix
If Cloudflare is connected and the name is in that account, the row does not just tell you the record is missing — it offers the one action that settles it:
- Create the DNS record when the name resolves to nothing yet. The panel writes a proxied A record for this server. Nothing is being replaced, so it does not ask twice.
- Point this at my server when the name already goes somewhere else. This one asks first and names the current value, because it changes DNS that is live.
If the address is a CNAME — very common for www, which is often set to point at your root domain — the panel cannot edit it into an A record; Cloudflare does not allow that. It removes the CNAME and creates the A record instead, and the confirmation says so, including that the name will not resolve for the moment in between. Everything else is the same.
Two things worth knowing about a www set up this way:
- It counts as pointed. If
www.example.comis a CNAME toexample.com, andexample.compoints at this server, thenwwwreaches this server too, and the panel reads it that way. - You do not have to change it. A CNAME to your root domain is a perfectly good arrangement. Repoint it only if you want
wwwto have its own record.
DNS changes are not instant. A few minutes is normal, and some providers take longer. The row tells you what the name currently resolves to, so you can see the change arrive.
3. Get HTTPS
Press Get free SSL on the row. The button stays disabled until the name is pointed.
The panel checks DNS again, asks Let's Encrypt for a certificate, writes the web server configuration and reloads it. You watch the log as it runs. It takes under a minute.
Expected result: the chip turns to secured, and https://your-domain opens with a padlock.
There are two ways the panel can prove to Let's Encrypt that the name is yours, and it picks the better one automatically:
- Through Cloudflare (DNS-01). When a stored Cloudflare token manages the name's zone, the panel proves control by writing a temporary DNS record. This needs no port 80 at all, works with the orange cloud on, and produces a real certificate that satisfies Cloudflare's strictest setting.
- Over port 80 (HTTP-01). Otherwise Let's Encrypt fetches a file from your server over plain
http, so port 80 has to be reachable.
The log says which one ran. Renewal is automatic: a daily job renews every certificate before it expires, and the web server is reloaded for each one separately, so one certificate with a problem can never freeze the others. There is nothing to remember and nothing to pay.
If you use Cloudflare
Every record the panel creates is proxied — that is the whole point of having Cloudflare there, and it is not optional in this panel.
Press Get free SSL as normal and the panel handles the rest:
- The usual case. With a Cloudflare token connected, it gets a real Let's Encrypt certificate by writing a DNS record, straight through the proxy. Set Cloudflare's SSL/TLS mode to Full (strict).
- Without a token, it first tries for a real certificate through the proxy over port 80. If that cannot pass on your zone, it installs a certificate the server signs itself, for the Cloudflare-to-server leg only. Your visitors still get Cloudflare's own trusted certificate. Set Cloudflare's SSL/TLS mode to Full — not Full (strict).
The panel tells you which of the three happened, in the log and on the page. Connecting a token is worth the five minutes: it removes the self-signed case entirely.
Keep one group consistent. One certificate serves one mode, so all the names of one card must be either all proxied or all direct — not a mix. The panel says so and leaves the odd one out of the certificate rather than breaking the rest.
Adding more names to one project
Add as many as you like to a card, and give each one its own certificate with Get free SSL. A common pair is example.com and www.example.com.
Make primary changes which name is the main one. For the admin site, the primary is the address the app and the mobile apps switch to, so change it only when you mean it.
Remove takes a name off this server. Visitors using it stop reaching the site. The name itself still belongs to you at your provider. The admin site's primary name cannot be removed — replace it instead.
What happens to the DNS record. By default, nothing: the record stays where it is and keeps pointing at this server, with no site behind it. If the name is on the Cloudflare account connected here, the dialog offers a tick box to delete the record at the same time — off by default, because deleting DNS cannot be undone. It only ever touches the one record for that exact name, and only when that record points at this server; a record aimed somewhere else is left alone and the panel says so. If the name is not on a Cloudflare account this panel manages, the dialog tells you where to go and delete it yourself.
If the name you removed was secured, the panel warns you that the certificate still lists it, and tells you to press Get SSL on the names you kept. Do it. Renewal has to prove every name on a certificate, so a certificate still listing a name that no longer points here stops renewing — and the names you kept go insecure about sixty days later, with nothing in between saying why. The panel does not re-issue by itself, because Let's Encrypt limits how many certificates a set of names may get each week and a tidy-up session can burn through that quietly.
A newly added name has no certificate until you press Get free SSL for that name.
One web address, or both: example.com and www.example.com
If your address is a root domain — example.com rather than shop.example.com — then visitors will type both spellings, and www points at the same server. The panel notices this and offers you a choice on that card.
This is only for root domains. A subdomain has no second spelling: nothing sensible sits at www.shop.example.com, and Cloudflare's free certificate does not reach two labels deep, so the panel does not offer it there.
If only one of the pair is added
The card suggests the other one with an Add www.example.com button. Press it, then Get free SSL — one certificate covers both names.
Once both are added
A small block appears with three choices:
| Choice | What visitors get |
|---|---|
| Serve both addresses | Either address opens the site directly. Nobody is redirected. This is the default. |
| Send example.com to www.example.com | The www address is the real one. Anyone typing the bare domain is moved to it, keeping the rest of the link. |
| Send www.example.com to example.com | The bare domain is the real one, and www is moved to it. |
Pick one and the panel writes it immediately. Nothing goes offline.
Why you might want one. Search engines treat the two spellings as two addresses and prefer being told which one is real, and your own links stay consistent. If you have no preference, leaving both switched on is perfectly fine — this is a tidiness choice, not a requirement.
The one rule: you can only redirect to the primary
One of the three choices is greyed out, and it is worth knowing why rather than wondering.
The primary address — the one marked primary on the card — is the address the application itself answers on. For the admin site, 6ammart registers its admin panel and its whole API against that exact hostname. Send that name somewhere else and every API call answers "not found" while the panel's own pages still look fine, which is a confusing failure to be handed.
So the panel only ever lets you redirect a name to the primary. If you want the other one to be the real address:
- Press Make primary on it. The panel moves the application's address for you and rebuilds its cache — that is one job, and it tells you when it is done.
- Then set the redirect on the name you just demoted.
It costs nothing
The redirect happens in the web server, before any of your shop's code runs — no PHP, no database, no page render. It is the cheapest thing a web server can do with a request, and it does not slow the site down.
Certificates and renewal
Both names go on one certificate, so there is nothing extra to renew and nothing extra to remember. Renewal keeps working through a redirect: the panel leaves the certificate-check path open on the redirected name deliberately, which is what a certificate authority reads when it renews.
Set the redirect after both names have their certificate. If you set it first, the panel tells you the other name still needs one — the redirect would otherwise send visitors to an address their browser warns about.
Turning it off
Choose Serve both addresses again. Both names go back to opening the site directly, and nothing else changes.
Live updates and the websocket address
The same choice appears on the Live updates card when its address is a root domain, and it works the same way. In practice this is rare: live updates normally share your main address, and nothing connects to a www form of a websocket endpoint — so if that card is on a subdomain, you will not see the block at all, which is correct.
How to check it worked
- The row shows all three chips: added, pointed, secured.
https://your-domainopens with a padlock and no warning.- Server → Health shows no certificate problems.
sudo sixpanel ssl statuslists the certificate, its issuer and the days left.
If it went wrong
"does not resolve to \<ip\>" The A record is missing, wrong, or has not spread yet. Fix it, wait a few minutes, press Get free SSL again.
The certificate step times out When the panel is using the port-80 method, port 80 must be open to the internet — or, behind Cloudflare, to Cloudflare's addresses. See The three ports. Connecting a Cloudflare token removes this dependency altogether.
"ACME_EMAIL is not set" / the log says the email address is unusable Let's Encrypt needs a real email address. Set it under Settings, then try again. Without one the panel can only write a self-signed certificate.
Cloudflare error 526 (Invalid SSL certificate) Your zone is set to Full (strict) but the server is using a self-signed certificate. Either press Get free SSL again — if the check can pass now, the panel upgrades to a real certificate by itself — or set the zone to Full.
The panel refused a name and suggested a different spelling That name would sit more than one level below your Cloudflare domain, where the free Cloudflare certificate does not reach. Use the spelling the panel offers (dash-shop.example.com rather than dash.shop.example.com).
"too many certificates" Let's Encrypt limits how many certificates one set of names may get per week. Wait, or use a slightly different set of names.
The panel's own address Giving the panel its own domain is a different setting, on the Security page. Read the lock-out warning in First login before you use it.
More causes and fixes: When something is broken.
কিছু বুঝতে অসুবিধা হচ্ছে?Tia-কে জিজ্ঞাসা করুন