Netlify

Netlify certificate expired: provisioning and DNS

Netlify provisions and renews Let's Encrypt certificates automatically. The retry schedule, the four documented failure causes, and the fixes.

Netlify renews certificates automatically, but leftover AAAA records, multiple A records, DNSSEC failures, or restrictive CAA records can block issuance. Inspect the custom domain under "Domain management > HTTPS," correct those DNS conflicts, run the documented debugging check, and recheck the live certificate after Netlify retries provisioning.

Why Netlify does this

Netlify's docs: "When you add a custom domain, Netlify automatically attempts to issue an SSL certificate. If the initial attempt fails, we retry every 10 minutes for the first 24 hours, then once every hour for the following two days". Their HTTPS page: "Certificates are generated and renewed automatically as needed". When provisioning fails, their troubleshooting page lists the causes: "Leftover AAAA records (IPv6)", "Multiple A records", "DNSSEC conflicts", and "CAA record restrictions": "If your CAA record doesn't include Let's Encrypt, certificate provisioning will fail". The dashboard error strings include "We could not provision a Let's Encrypt certificate for your custom domain" and "DNS verification failed".

Check it right now

Before changing anything, confirm what a crawler actually sees. The check is free, takes one URL and needs no account.

Run the check

How to fix it

  1. From the project dashboard, go to Domain management > HTTPS and read the certificate status.
  2. Check external DNS: the A record for the bare domain should point to 75.2.60.5 and the www CNAME to your sitename.netlify.app.
  3. Remove leftover AAAA records and any second A record; their docs name both as certificate failures.
  4. Check the CAA record: it must include letsencrypt.org, or be removed entirely.
  5. If DNS looks right, run the domain through Let's Debug as their docs instruct.
  6. Re-check the certificate expiry with the free SSL and domain checker below.

Why it happens again

Certificates renew automatically, so the failure happens at provisioning time, which comes once per domain and once after every DNS change. Move the domain, add a CAA record for another provider, or leave an old AAAA record behind, and the certificate that had been quietly renewing stops. The DNS is usually changed by a different person than the one who set up the site.

stillindexed re-checks the URLs you give it every 30 minutes on Starter and alerts when a directive changes, at most 30 minutes after it does. It is a monitor rather than a crawler: it watches a list you choose and tells you when one of seven things changes. Card first, no trial, and a 30 day refund.

See what monitoring covers

Catching it next time

Fixing it once is the easy half. The setting that caused this can be changed again by anyone with access, and the page will keep returning 200 while it happens.

Other ways Netlify loses pages

An expired or expiring TLS certificate, on other platforms

Sources

Every claim about Netlify above is from their own documentation, read on 2026-08-30. Platforms change their settings; if one of these is out of date, their page wins and we would like to know.