Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

You can use acme.sh to obtain and renew a free Let’s Encrypt certificate for a Namecheap domain. For unattended DNS validation, your domain’s DNS must be managed where acme.sh can update the challenge records; the Namecheap DNS plugin requires API credentials and has an important records-handling caveat. This is a do-it-yourself ACME setup, not Namecheap’s own SSL product or native Let’s Encrypt integration.

Choose the right SSL route for your Namecheap domain

The choice depends on who manages your DNS, how much server access you have, and whether you need a certificate issued only or installed automatically as well.

Route Best suited to Key requirement or limitation
acme.sh with Namecheap DNS API Domains using Namecheap-managed DNS where you can use API credentials Requires a Namecheap API key, username, and source IP. The plugin reads and reapplies domain records, so back them up before use.
acme.sh webroot or server validation Operators with access to the website’s webroot or server The ACME challenge must reach the correct server. Issuing a certificate may not configure the web server to use it.
acme.sh manual DNS Situations without compatible DNS API access You must manually add challenge TXT records for each issuance or renewal; this is not fully unattended.
Namecheap SSL Proxy Website owners who want Namecheap to proxy the site and reduce server administration Namecheap says the domain must use Namecheap DNS. This is a separate Namecheap offering, not the free acme.sh workflow.
Namecheap SSL Manager Buyers of Namecheap SSL who need installation on cPanel, Apache, or NGINX This is a product-specific paid SSL workflow with setup through cPanel or a terminal command on a root/admin server.

Namecheap’s SSL coverage guidance, updated September 9, 2026, says its ACME support is scheduled for November–December 2026. That is a planned availability window, not confirmation that the feature is live. Check the page for current status before relying on it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What you need for unattended renewal

  • Control of authoritative DNS: The DNS provider that publishes your domain’s records must support the validation method you choose. A Namecheap domain registration alone does not establish that Namecheap is managing its DNS.
  • API access for DNS automation: The Namecheap plugin needs an API key, username, and source IP, identified by acme.sh as NAMECHEAP_API_KEY, NAMECHEAP_USERNAME, and NAMECHEAP_SOURCEIP.
  • A safe DNS recovery plan: The acme.sh Namecheap DNS plugin warns that, because of Namecheap API limitations, it reads and reapplies all records for the domain. Save a copy of the current DNS records and know how to restore them before enabling the plugin.
  • Server access for deployment: Plan how the issued certificate and private key will be installed and how your web server will be configured to use them. Validation and issuance alone do not guarantee deployment.

Namecheap’s DNS API documentation lists methods for retrieving and setting host records. It also explains that free host-record management and some value-added services require Namecheap default DNS; custom nameservers can affect Namecheap-managed services. Confirm where your authoritative DNS is hosted before following a Namecheap DNS API procedure.

Set up acme.sh with Namecheap DNS validation

Use DNS validation when the domain’s DNS is managed through Namecheap and you can safely provide the plugin’s required API details. The plugin’s documented variable names are shown below; use the exact credential values and source IP for your account. Store secrets securely rather than putting them in a public script or repository.

  1. Back up your DNS records. Record the existing host records and any nonstandard entries so you can restore them if needed.
  2. Confirm DNS and API eligibility. Make sure the domain uses Namecheap DNS and that API access is available for your account and source IP. If your domain uses another DNS provider’s nameservers, use that provider’s supported DNS integration instead.
  3. Install acme.sh and configure the Namecheap plugin. Follow the current installation and plugin instructions in the acme.sh README and its Namecheap DNS plugin documentation. Provide NAMECHEAP_API_KEY, NAMECHEAP_USERNAME, and NAMECHEAP_SOURCEIP through the method supported by your installation.
  4. Request a certificate for the intended names. Specify the exact hostname or hostnames you need. A certificate for one name does not automatically cover every subdomain; wildcard issuance requires DNS validation.
  5. Install the certificate for your server. Use acme.sh’s documented installation/deployment approach for your web server, then configure and reload that server as appropriate. Do not assume successful issuance means HTTPS is already using the new certificate.
  6. Verify the live site and renewal path. Confirm the served certificate covers the intended hostname and that the deployment process will run when acme.sh renews it. Monitor the renewal and web-server reload path for failures.

When DNS API automation is not available

Use webroot or server validation when you control the site

The acme.sh README documents webroot, standalone, and NGINX issuance modes as well as DNS API methods. Choose a method whose challenge can reach the correct server. Depending on the mode, you may need access to the webroot or to the ports and server configuration used for validation. Check the mode’s instructions for whether it also installs the certificate; some modes issue a certificate but leave server configuration to you.

Manual DNS is a fallback, not unattended renewal

With manual DNS mode, acme.sh provides the challenge value and you add the corresponding _acme-challenge TXT record at your DNS provider. The manual step must be repeated for later renewal, so this option does not meet a fully unattended-renewal goal by itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Understand renewal timing and the separate Namecheap SSL products

The current acme.sh README, accessed October 7, 2026, says the client renews certificates automatically every 30 days or earlier when the certificate authority’s ACME Renewal Information (ARI) calls for it. This is acme.sh’s stated renewal behavior, not a claim that every certificate has a 30-day validity period or that every server deployment will succeed without monitoring.

Namecheap describes a different schedule for its own SSL products: its coverage page says certificates in the SSL Proxy and SSL Manager workflows are replaced every 200 days during the purchased term, and warns that missing a required reissue can stop HTTPS. That schedule applies to those Namecheap offerings, not to a Let’s Encrypt certificate requested through acme.sh.

Rank #4
Sale
Adams Gift Certificate Book, Carbonless, Single Paper, 3.4 x 8 Inches, White/Canary, 2-Part, 25 Numbered Certificates Plus Store Sign (GFTC1)
  • 2-part carbonless unit set
  • Consecutive numbering
  • Includes Gift Certificates Available sign
  • 25 certificates with envelopes per package
  • White/canary form sequence

Troubleshoot common setup failures

  • DNS challenge cannot be completed: Check which nameservers are authoritative for the domain. If they are not Namecheap’s, the Namecheap API plugin cannot update the active DNS zone; use the authoritative provider’s integration or another validation method.
  • API authentication or authorization fails: Recheck the API key, username, and source IP configured for the plugin, and confirm that API access is enabled and allowed for that source.
  • DNS records change unexpectedly: Stop and compare the live zone with your backup. The plugin’s documented behavior involves reading and reapplying all domain records; restore records carefully and investigate before retrying.
  • Certificate issuance succeeds but the site still shows an old or invalid certificate: Check certificate installation paths, web-server configuration, and whether the server was reloaded after deployment. Issuance does not necessarily perform those steps.
  • Renewal requires a person to add a TXT record: That is the expected limitation of manual DNS mode. Move to a supported DNS API integration or another automated validation and deployment path if unattended renewal is required.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.