Likely causes, most common first
Cause 1 · in 1 of 5 matching casesExtra A or leftover AAAA records at the apex
With external DNS, the bare domain should have one A record pointing to 75.2.60.5. A leftover AAAA record from a previous host, or a second A record, stops the certificate from being issued. The record you added may be correct while the old one is still there.
How to tell: With external DNS, dig or Let's Debug returns an AAAA answer, or more than one A record, for the bare domain.
Cause 2 · in 1 of 5 matching casesThe Netlify DNS zone isn't serving the apex
With Netlify DNS, the registrar has to use Netlify's name servers, DNSSEC has to be turned off, and the zone needs records for both the apex and www. If the Netlify DNS zone is inactive, Netlify can't create or update the Let's Encrypt certificate. Netlify DNS doesn't support DNSSEC.
How to tell: An NS lookup or whois doesn't list the Netlify name servers, DNSViz shows DNSSEC enabled, or the bare domain returns no answer.
Cause 3 · in 1 of 5 matching casesAnother domain on the site doesn't point to Netlify
The certificate covers the site's domain aliases, but each alias must point to Netlify in DNS before the certificate is issued. Otherwise that alias is left off. A domain added by mistake, or a www or alias name still on an old host, leaves that name uncovered. Netlify can get a certificate for one name and not another.
How to tell: The curl header check shows server: Netlify for some of the site's domains but not for others.
A CAA record or a proxy keeps Let's Encrypt out
Netlify-managed certificates come from Let's Encrypt, so provisioning fails if a CAA record doesn't include Let's Encrypt. A proxy in front of the site, such as Cloudflare's "accelerate and protect" mode, also blocks it, because Netlify must terminate TLS to provision a certificate.
How to tell: dig CAA lists a certificate authority but not letsencrypt.org, or the curl check doesn't show server: Netlify.
Questions
How long should I wait before treating provisioning as stuck?
Netlify retries every 10 minutes for the first 24 hours, then hourly for the following two days. If there's still no certificate after 24 hours, Netlify's docs say DNS is probably misconfigured and needs your attention.
Why does the apex have a certificate but www doesn't?
Netlify can get a certificate for one name and not another. Check that both the apex and www have records pointing to Netlify, then select Renew certificate in Domain management > HTTPS.
Can I keep DNSSEC switched on?
Not with Netlify DNS, which doesn't support DNSSEC. To keep DNSSEC enabled, stop using Netlify DNS and use external DNS instead.
What should I send Netlify Support if none of this works?
Send your project (site) name, whether you use external DNS or Netlify DNS, and a summary of the troubleshooting steps you've taken.