Cloudflare

Cloudflare certificate expired: Universal SSL renewal

Cloudflare renews Universal SSL certificates automatically, and the documented failures are DCV and CAA. The windows, the causes, and the checks.

Cloudflare Universal SSL renews automatically, but Domain Control Validation can fail when DNS does not point through Cloudflare or CAA records exclude the certificate authority. Check the certificate status, repair the documented DCV DNS records, review CAA on the domain and CNAME target, confirm proxying, then rerun the certificate check.

Why Cloudflare does this

Cloudflare manages the edge certificate and renewal is automatic: "For certificates managed by Cloudflare, attempts to renew start at the auto renewal period and continue up until 24 hours before expiration." Universal SSL certificates have "a 90-day validity period" and "The auto renewal period starts 30 days before expiration". The documented failure is validation, not billing: on a CNAME (partial) setup, "make sure Domain control validation (DCV) is configured correctly". CAA is the other documented blocker: "If you have CAA records on your domain, they must permit the certificate authority (CA) that Cloudflare uses", and their gotcha: "If your hostname CNAMEs to a domain whose zone has restrictive CAA records, those records take precedence". Let's Encrypt's own FAQ fixes the lifetime: "Our default certificates are valid for 90 days".

Check it right now

Before changing anything, confirm what a crawler actually sees. The check is free, takes one URL and needs no account.

Run the check

How to fix it

  1. In the Cloudflare dashboard, open the domain and check the certificate status under SSL/TLS; statuses include Initializing, Pending Validation and Active.
  2. If it is stuck on Pending Validation, check DCV: on a partial (CNAME) setup the validation records must be present at your DNS provider.
  3. Run dig for CAA records on the domain and confirm they permit the CA Cloudflare uses; also check CAA on any CNAME target.
  4. Confirm the hostname is proxied, since Universal SSL only covers proxied hostnames.
  5. Re-check the certificate expiry with the free SSL and domain checker below.

Why it happens again

Renewal runs every 90 days forever, so the only day it matters is a day nobody is watching. The two documented failure causes are both quiet: a CAA record added for another provider, and a CNAME setup whose validation records were removed during a DNS cleanup. Cloudflare deploys a backup certificate only if another valid certificate exists for the hostname.

stillindexed re-checks the URLs you give it every 30 minutes on Starter and alerts when a directive changes, at most 30 minutes after it does. It is a monitor rather than a crawler: it watches a list you choose and tells you when one of seven things changes. Card first, no trial, and a 30 day refund.

See what monitoring covers

Catching it next time

Fixing it once is the easy half. The setting that caused this can be changed again by anyone with access, and the page will keep returning 200 while it happens.

Other ways Cloudflare loses pages

An expired or expiring TLS certificate, on other platforms

Sources

Every claim about Cloudflare above is from their own documentation, read on 2026-08-30. Platforms change their settings; if one of these is out of date, their page wins and we would like to know.