Fix · Custom domain SSL not working but the default URL loads

Netlify SSL certificate not provisioning, DNS verified

Netlify says DNS verification passed and the netlify.app URL serves HTTPS, but Domain management > HTTPS still shows no certificate for the custom domain, or the certificate won't renew. The cause is usually still in DNS: an extra A or AAAA record at the apex, DNSSEC or an inactive Netlify DNS zone, a CAA record, a proxy, or another domain on the site that doesn't point to Netlify.

Likely causes, most common first

Cause 1 · in 1 of 5 matching cases

Extra A or leftover AAAA records at the apex

With external DNS, the bare domain should have one A record pointing to 75.2.60.5. A leftover AAAA record from a previous host, or a second A record, stops the certificate from being issued. The record you added may be correct while the old one is still there.

How to tell: With external DNS, dig or Let's Debug returns an AAAA answer, or more than one A record, for the bare domain.

Cause 2 · in 1 of 5 matching cases

The Netlify DNS zone isn't serving the apex

With Netlify DNS, the registrar has to use Netlify's name servers, DNSSEC has to be turned off, and the zone needs records for both the apex and www. If the Netlify DNS zone is inactive, Netlify can't create or update the Let's Encrypt certificate. Netlify DNS doesn't support DNSSEC.

How to tell: An NS lookup or whois doesn't list the Netlify name servers, DNSViz shows DNSSEC enabled, or the bare domain returns no answer.

Cause 3 · in 1 of 5 matching cases

Another domain on the site doesn't point to Netlify

The certificate covers the site's domain aliases, but each alias must point to Netlify in DNS before the certificate is issued. Otherwise that alias is left off. A domain added by mistake, or a www or alias name still on an old host, leaves that name uncovered. Netlify can get a certificate for one name and not another.

How to tell: The curl header check shows server: Netlify for some of the site's domains but not for others.

Cause 4

A CAA record or a proxy keeps Let's Encrypt out

Netlify-managed certificates come from Let's Encrypt, so provisioning fails if a CAA record doesn't include Let's Encrypt. A proxy in front of the site, such as Cloudflare's "accelerate and protect" mode, also blocks it, because Netlify must terminate TLS to provision a certificate.

How to tell: dig CAA lists a certificate authority but not letsencrypt.org, or the curl check doesn't show server: Netlify.

Check and fix it, step by step

  1. Read the certificate state in the dashboard

    Open Domain management > HTTPS and note the exact error message. Netlify retries every 10 minutes for the first 24 hours, then once an hour for the next two days. If there's still no certificate after 24 hours, DNS is probably misconfigured.

    Docs: docs.netlify.com →

  2. Confirm each domain on the site is served by Netlify

    Check the response headers of every domain connected to the site, including www and any aliases. Each one should show server: Netlify.

    curl -s -v http://example.com 2>&1 | grep -i server
    curl -s -v http://www.example.com 2>&1 | grep -i server

    Docs: docs.netlify.com →

  3. Query the apex records from a public resolver

    With external DNS, the bare domain should return 75.2.60.5 and www should be a CNAME to your-site.netlify.app. With Netlify DNS, check the NS records instead: they should list your Netlify name servers.

    dig +short A example.com @8.8.8.8
    dig +short AAAA example.com @8.8.8.8
    dig +short CAA example.com @8.8.8.8
    dig +short CNAME www.example.com @8.8.8.8
    dig +short NS example.com @8.8.8.8

    Docs: docs.netlify.com →

  4. Run Let's Debug against the domain

    If propagation looks complete but provisioning still fails, enter the custom domain at Let's Debug. It reports what Let's Encrypt sees, including leftover AAAA records, multiple A records, DNSSEC problems and CAA restrictions.

    Docs: docs.netlify.com →

  5. Delete stray apex records and allow Let's Encrypt in CAA

    With external DNS, remove all AAAA records and any A record other than 75.2.60.5 at your registrar or DNS host. Then update the CAA record to allow Let's Encrypt, or remove it. The record below follows Netlify's example and restricts issuance to Netlify's Let's Encrypt account.

    example.com. 300 IN CAA 0 issue "letsencrypt.org;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/54403714"

    Docs: docs.netlify.com →

  6. On Netlify DNS, turn off DNSSEC at the registrar

    Use DNSViz to find where DNSSEC is enabled, then disable it with the registrar or the previous DNS host. If you need to keep DNSSEC, use external DNS instead of Netlify DNS.

    Docs: docs.netlify.com →

  7. Remove the proxy, then select Renew certificate

    Disable any routing through another service so that Netlify terminates TLS. If one name has a certificate and another doesn't, select Renew certificate. You can also use Google Public DNS's Flush Cache tool to clear old cached values.

    Docs: docs.netlify.com →

Quick check: External DNS only: dig +short A example.com; dig +short AAAA example.com # want one A 75.2.60.5, no AAAA

How often this shows up in our data

5 of the 344 verified cases from the last 12 months in our data match this symptom (1.5%). The most common cause was “Extra A or leftover AAAA records at the apex” (1 of 5); 2 didn't show which cause. How we collect and verify cases.

Questions

How long should I wait before treating provisioning as stuck?

Netlify retries every 10 minutes for the first 24 hours, then hourly for the following two days. If there's still no certificate after 24 hours, Netlify's docs say DNS is probably misconfigured and needs your attention.


Why does the apex have a certificate but www doesn't?

Netlify can get a certificate for one name and not another. Check that both the apex and www have records pointing to Netlify, then select Renew certificate in Domain management > HTTPS.


Can I keep DNSSEC switched on?

Not with Netlify DNS, which doesn't support DNSSEC. To keep DNSSEC enabled, stop using Netlify DNS and use external DNS instead.


What should I send Netlify Support if none of this works?

Send your project (site) name, whether you use external DNS or Netlify DNS, and a summary of the troubleshooting steps you've taken.


Sources

Every cause and step above was checked against these pages on 1 Oct 2026.

The broader pattern

This is one symptom of a wider failure pattern: Custom domain SSL not working but the default URL loads. The guide covers every cause we see for it, on any stack.

Get a heads-up when Netlify breaks something

Netlify

Leave your email and we'll let you know when something big changes for Netlify. Unsubscribe any time by replying. Gemmein Limited. Research terms · Privacy

← All fixes