Activating SSL
Activate a free Let's Encrypt SSL certificate for your website via the SSL It! extension in Plesk.
Installing an SSL certificate
Go to Websites & Domains → choose your domain.
Click SSL/TLS Certificates.
Under Let's Encrypt, click Install.
Enter your e-mail address (for renewal notifications).
Select what to secure:
The main domainIncluding thewwwsubdomainWildcard (all subdomains) β if availableThe webmail subdomainThe mail domain (for IMAP/POP/SMTP)Click Get it for free.
Let's Encrypt certificates renew automatically every 90 days β 30 days before expiry. You don't need to do anything for this.
Forcing HTTPS
After installation you'll want visitors to always see the secure version of your site:
Go to Websites & Domains → Hosting Settings.
Check Permanent SEO-safe 301 redirect from HTTP to HTTPS.
Click OK.
Enabling HSTS
For extra security, you can activate HSTS (HTTP Strict Transport Security). This tells browsers your site is only reachable via HTTPS:
Go to SSL/TLS Certificates for your domain.
Enable HSTS.
Only enable HSTS if you're certain your SSL certificate will always stay active. If the certificate expires while HSTS is active, visitors won't be able to reach your website at all β not even over HTTP.