What is an SSL Certificate and why do you need It?
An SSL (Secure Sockets Layer) Certificate is a digital security technology that encrypts the data sent between a website and a browser. In the context of email marketing, it is used to secure your tracking domains.
When you send an email, Elastic Email replaces your links with tracking links to monitor clicks and engagement. By default, these links use a standard connection.
However, adding an SSL certificate to your tracking domain provides several key benefits:
Improved deliverability: mailbox providers (like Gmail or Outlook) prefer secure links. Emails with HTTPS links are less likely to be flagged as spam.
User trust: when a recipient clicks a link, their browser won't show a "Not Secure" warning. This builds confidence in your brand.
Data security: it ensures that any information passed through the tracking link is encrypted and protected from interception.
How the Self-Service installation works
Previously, setting up SSL for your tracking domain required contacting Customer Support. We have now automated this process, allowing you to secure your domains independently.
1. Preparing your domain
Before you can secure your tracking domain, you must ensure your DNS records are correctly configured and verified.
SPF and CNAME Records: your domain must have the required SPF and Tracking CNAME records pointing to Elastic Email.
Verification: navigate to your Domains list in the settings. If your domain is new, it will show a status of "Requires DNS verification". Click "Verify domain" once you have updated your records at your domain provider.
You can learn how to properly verify your domain in the guide "How to verify your domain".
2. Automatic securing
Once your domain's DNS is verified, the SSL installation is triggered automatically.
Status: Securing... – you will see this status while the system provisions your certificate. This usually takes a few minutes but can take up to 24 hours depending on how fast your DNS changes spread across the internet.
Status: Secured – once complete, your domain will show as "Secured." Your tracking links will now automatically use https://.
3. Handling older (Pre-verified ) domains
If you verified your domain before this automated feature was released, your status might show as "Ready to secure."
To trigger the installation, simply go to the "View Details" section of that domain and click "Re-verify." This will put your domain into the automated queue.
Monitoring and maintenance
You can monitor the security status of all your domains at a glance in the Tracking Security (SSL) column in your Domains list.
Status | What it means | Action required |
Secured | Your certificate is active and valid. | None. The certificate auto-renews before it expires. |
Securing... | The certificate is being installed. | No action needed; please wait for propagation. |
Installation failed | The automated process couldn't finish. | Check your DNS settings and click "Re-verify" to try again. |
Certificate expired | The certificate lapsed, usually due to a DNS change. | Fix your DNS records and click "Re-verify" to reinstall. |
Important note on DNS changes
The system includes a 3-day grace period. If you accidentally change or delete your tracking DNS record, the "Secured" status will remain for 3 days to give you time to fix it before the certificate is removed. If the record isn't corrected, the domain will revert to "Requires DNS verification."
Need more help? If you encounter persistent installation failures, feel free to reach out to our Customer Support team.

