Comodo Multi-Domain Wildcard SSL (OV) Review 2026
An Organization Validated certificate that combines SAN-based multi-domain coverage with wildcard subdomain support, issued by Sectigo. Here is what it secures, what the validation paperwork looks like, and where it earns its higher price over the standard Multi-Domain SSL.
What Comodo Multi-Domain Wildcard SSL Covers
Comodo Multi-Domain Wildcard SSL secures several distinct domains on one certificate, and every subdomain under each of those domains, without listing each subdomain individually. A single order can protect a base domain, a handful of client domains, and every present or future subdomain those domains create, all under one renewal cycle.
Validation runs at the OV level, so Sectigo confirms the requesting business is a real, registered entity before issuing the certificate. That business name then appears in the certificate's detail view and, on resellers that support it, in a dynamic site seal. Coverage tops out at 250 domains on most reseller packages.
How Validation Works
Validation for this certificate has two parts: proving control of every base domain and wildcard entry, and proving the requesting organization is a legitimate, verifiable business. The wildcard structure changes what counts as valid domain control evidence compared to a standard OV certificate.
Domain Control Validation
DNS TXT/CNAME record or email confirmation for each base domain. HTTP file validation is not accepted for wildcard entries — teams that automated single-domain issuance around a file upload need a DNS-based workflow for this certificate instead.
Business Verification
Sectigo checks company registration, physical address, and domain ownership against public records such as Dun & Bradstreet or a listed BBB profile. This confirms the legal existence of the requesting organization and the information that appears in the certificate and site seal.
Telephone or Alternate Verification
A callback to a listed business number, or an accepted substitute such as a Dun & Bradstreet listing or Legal Opinion Letter. Standard business directory listings no longer satisfy this step.
At a Glance
The Domain Math: What "Unlimited Subdomains" Actually Means
The word "unlimited" applies to subdomains under each listed base domain, not to the number of base domains itself. A certificate covering three base domains gives unlimited subdomain coverage under each of those three, but a fourth unrelated domain still needs to be added as a new SAN entry with its own validation.
| Scenario | Covered Without Extra SANs? |
|---|---|
| blog.example.com, shop.example.com, mail.example.com (all under example.com) | Yes — once example.com is on the certificate as a wildcard entry |
| example.com and example2.com, each with their own subdomains | No — example2.com needs its own SAN entry, which then also gets unlimited subdomain coverage |
| A brand-new subdomain launched next quarter under an already-listed domain | Yes — no reissue needed for a domain already covered by a wildcard SAN |
| A second-level subdomain like staging.api.example.com | No — wildcard covers one level only, second-level nesting is outside scope |
What It Actually Costs
Pricing runs meaningfully higher than the standard Multi-Domain SSL because of the added wildcard SAN logic and, on most sellers, a larger base warranty. The domain count bundled into the base price is not standardized, so a lower headline price can still mean more included wildcard SANs at one seller than another.
Key Changes for This Certificate in 2026
The same CA/Browser Forum changes affecting every publicly trusted certificate apply here, and they interact with the wildcard structure in a way flat Multi-Domain certificates do not experience.
Shorter Certificate Validity
Maximum validity per issuance dropped to 200 days as of March 2026. On a certificate carrying several wildcard SANs, a single reissue event has to revalidate every base domain at once, since wildcard SAN validation cannot be renewed piecemeal the way individual subdomains could be added over time on a non-wildcard certificate.
Domain Validation Reuse Window Shortened
The window for reusing a prior domain validation result before repeating it has been cut. Combined with the ban on HTTP validation for wildcard entries, this makes DNS-based automation close to mandatory for anyone running this certificate across more than a couple of domains, rather than optional convenience.
Strengths and Limitations
Strengths
- Covers unlimited subdomains under every listed base domain, eliminating per-subdomain SAN purchases
- OV-level business verification shows in the certificate details for accountability across a multi-domain footprint
- Unlimited server licensing supports shared hosting environments running many client sites
- Up to $250,000 warranty on most reseller listings
- New subdomains under listed base domains are covered automatically without reissuance
Limitations
- HTTP file validation is not accepted for wildcard SAN entries, forcing a DNS-based workflow
- Requires SNI support on the serving infrastructure, ruling out some legacy load balancers
- Site seal type (dynamic vs static) is inconsistent across resellers
- Meaningfully more expensive than the standard Multi-Domain SSL when subdomain coverage is not needed
- Business verification and telephone checks add the same 1 to 3 business day delay as any OV product
Multi-Domain Wildcard SSL vs. Standard Multi-Domain SSL
The two certificates share the same OV validation process, the same root chain, and the same encryption strength. The entire difference comes down to whether subdomains need coverage, and that difference should drive the purchase decision.
Multi-Domain Wildcard SSL
Multi-Domain SSL (standard)
Who Should Use Comodo Multi-Domain Wildcard SSL
SaaS Platforms with Client Subdomains
Businesses issuing a subdomain per customer need coverage that scales without a SAN purchase for every new signup.
Agencies Hosting Multiple Client Sites
Managing several client domains, each running staging and www subdomains, consolidates into one certificate and one renewal date.
Enterprises with Departmental Subdomains
Organizations running mail, shop, support, and blog subdomains across more than one owned domain get full coverage without tracking individual SAN entries.
Single-Domain Sites Without Subdomains
A standard single-domain OV certificate covers this case at a lower price with no wasted wildcard capacity.
Flat Multi-Domain Portfolios
Businesses running several unrelated domains that do not use subdomains should buy the standard Multi-Domain SSL instead and skip the wildcard premium.
Legacy Infrastructure Without SNI
Environments running older load balancers or appliances without SNI support cannot serve this certificate correctly across shared hosting.
Frequently Asked Questions
Ready to Compare SSL Certificates?
Comodo Multi-Domain Wildcard SSL solves subdomain sprawl across multiple domains, but it is overkill for a flat domain portfolio. Compare it against the standard Multi-Domain SSL and other providers before committing to the wildcard premium.
