Compare the custom domain with the default address
Request the same path on both and compare the status code and the byte count. If only the custom domain returns a different size or fails the handshake, the problem is in DNS, the proxy, the certificate or the host's edge, not in your code.
curl -sS -o /dev/null -w '%{http_code} %{size_download} bytes\n' https://your-app.vercel.app/
curl -sS -o /dev/null -w '%{http_code} %{size_download} bytes\n' https://example.com/
Audit every DNS record for the hostname
Compare the answers with the exact records listed in your host's domain settings. Remove A and AAAA records that point at a previous host. Before you delete an _acme-challenge record, find out which provider it belongs to. Keep any NS records your current host asked you to add to delegate validation.
dig NS example.com +short
dig A example.com +short
dig AAAA example.com +short
dig CNAME www.example.com +short
dig TXT _acme-challenge.example.com +short
Let the validation request reach the host
A made-up token should return a plain 404 from your host, not a redirect, a login page or a cached page from the proxy. Route /.well-known/acme-challenge/* to the host on port 80 without caching, authentication or proxy-level redirects, or set the Cloudflare record to DNS only. If you keep Cloudflare proxying and the origin already forces HTTPS, set the SSL/TLS encryption mode to Full or Full (strict), not Flexible.
curl -sS -D - -o /dev/null http://example.com/.well-known/acme-challenge/test-token
Stop retrying a rate-limited renewal
Each failed attempt counts against the authorization-failure limit. Fix the DNS or proxy path first, test it with Let's Debug (letsdebug.net), then trigger one renewal. For wildcards, use the host's nameservers or delegate _acme-challenge to the host so it can complete DNS-01 on its own.
Detach the domain from old projects and check CAA
Remove the domain from any old project, team or host before you add it to the new one, and complete any TXT ownership check you are asked for. If a CAA policy exists at the hostname or a parent domain, it must allow your host's certificate authority. Vercel and Netlify issue certificates through Let's Encrypt.
dig CAA example.com +noall +answer
# if a policy exists, it must include:
# example.com. CAA 0 issue "letsencrypt.org"
Monitor the custom domain and alert on expiry
Point uptime checks and smoke tests at the custom domain, not the platform URL. Add an expiry check that fails when the certificate has fewer than 14 days left, so a stuck renewal pages you while there is still time to fix it.
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
| openssl x509 -noout -enddate -checkend 1209600
Escalate edge faults early, with evidence
If DNS and the certificate are correct and the default address works where the custom domain does not, open a support ticket. Include the hostname, timestamps, the browser error, your dig output and the curl comparison. Strip cookies and Authorization headers from anything you paste.