NK fully supports Let's Encrypt + Buypass + auto renewal. Available on all paid plans.
4 validation methods
- HTTP (http-01) — port 80 direct to local, simple non-CDN case
- Email (manual) — link sent to registered email, CF proxy irrelevant
- Email built-in — NK auto-receives and confirms. Requires MX to mx1.host.mw
- DNS (dns-01) — add CNAME record, or use NK built-in providers (Cloudflare / DNSPod / Namecheap / PowerDNS) with API token to auto-add TXT
Cron auto-renewal
NK scans all certs daily at 04:00. Less than 30 days remaining → auto-renew. Successful renewal also syncs to nodes in the same sync group.
ZeroSSL (Custom only)
plan_custom includes feat_ssl_zerossl: bring your own EAB account, bypass Let's Encrypt rate limits.