Vercel
Vercel certificate expired: custom certificates
Vercel generates certificates for every domain automatically, but uploaded certificates are your problem. The documented 5 day fallback.
Vercel renews generated certificates automatically, but an uploaded custom certificate remains your responsibility and can expire. Check the domain for a custom certificate, remove the expiring upload so Vercel can generate its default replacement, correct DNS if no custom upload exists, then verify the new live certificate.
Why Vercel does this
Vercel's docs: "By default, Vercel provides all domains with custom SSL certificates", meaning automatically generated ones. The failure mode is the uploaded certificate: "Vercel cannot automatically renew custom certificates. If a custom certificate is within 5 days of expiration, an automatically generated certificate will be served in its place to prevent downtime". Also documented: "if a custom certificate is uploaded and then later removed, Vercel will revert to the automatically generated certificate". An uploaded certificate is the only way a lapsed certificate reaches visitors on Vercel.
Check it right now
Before changing anything, confirm what a crawler actually sees. The check is free, takes one URL and needs no account.
How to fix it
- Open the team dashboard, go to Domains, and check whether a custom certificate is attached to the domain.
- If a custom certificate is present and near expiry, remove it: Vercel documents that the automatically generated certificate takes over again.
- If no custom certificate exists, renewal is automatic; check the domain's DNS instead, since provisioning requires the domain to point at Vercel.
- Re-check the certificate expiry with the free SSL and domain checker below.
Why it happens again
The uploaded certificate is ordered once by whoever handled the enterprise setup, and renewing it is an external process with no owner on the platform side. Vercel's 5 day fallback covers the expiry quietly, so the misconfiguration lives on unnoticed until the generated certificate fails for a different reason.
stillindexed re-checks the URLs you give it every 30 minutes on Starter and alerts when a directive changes, at most 30 minutes after it does. It is a monitor rather than a crawler: it watches a list you choose and tells you when one of seven things changes. Card first, no trial, and a 30 day refund.
Catching it next time
Fixing it once is the easy half. The setting that caused this can be changed again by anyone with access, and the page will keep returning 200 while it happens.
Other ways Vercel loses pages
An expired or expiring TLS certificate, on other platforms
Sources
Every claim about Vercel above is from their own documentation, read on 2026-08-30. Platforms change their settings; if one of these is out of date, their page wins and we would like to know.