🤖NEW:AI-Powered Incremental Builds — your site updates in under 30 seconds. See what's new →
troubleshooting

Troubleshooting DNS Propagation & SSL Certificate Issuance

Resolve SSL certificate provisioning delays, DNS CNAME mismatches, and domain verification blockers.

📋This is an interactive step-by-step HowTo guide with 3 verified installation steps.

Diagnosing Domain Verification Issues

Custom domains must resolve to Nimbica's Anycast edge IP or CNAME target before automated SSL certificates can be provisioned.

Common DNS Blockers

  • Conflicting A Records: Ensure old hosting A records on the subdomain have been removed so only the Nimbica CNAME record exists.
  • CAA Record Restrictions: If your domain has DNS CAA records, ensure letsencrypt.org is allowed to issue certificates.
  • Proxy Conflicts: If managing DNS in Cloudflare, set the record to DNS-only (Grey Cloud) during initial verification.

📋 Verified Execution Steps (3 Total Steps)

11. Check Global DNS Propagation

Use a DNS lookup tool (such as Nimbica DNS Checker or whatsmydns.net) to verify that your CNAME points to cname.nimbica.com globally.

22. Verify CAA Records

Ensure your domain allows Let's Encrypt certificate issuance: issue "letsencrypt.org".

33. Re-Trigger Verification in Nimbica

Click "Re-Verify Domain" in Nimbica Dashboard ➔ Domains. SSL certificates are issued within 60 seconds of resolution.

Was this documentation page helpful?
Last updated on 2026-09-07