Apex domain certificate stuck — "missing domains" despite clean DNS (growchi.co.uk)

Site: growchi.co.uk (Netlify site)
Domains: growchi.co.uk (apex) + www.growchi.co.uk (primary)

Issue:
www.growchi.co.uk works correctly over HTTPS. growchi.co.uk (apex) fails with ERR_SSL_PROTOCOL_ERROR, tested fresh/incognito across multiple networks. SSL/TLS certificate section in dashboard shows: “Certificate renewal incomplete: missing domains growchi.co.uk — unchanged since May 14.

What I’ve already tried (all from your troubleshooting guide):

  1. Confirmed DNS points correctly to Netlify — single A record @75.2.60.5 (originally had a second A record to 99.83.190.102, which Let’s Debug flagged as giving inconsistent ACME validation results; removed it, Let’s Debug now reports clean results)
  2. No CAA records present
  3. No domain forwarding/masking
  4. No third-party service (Cloudflare etc.) in front of the domain
  5. Flushed DNS cache via Google Public DNS’s cache flush tool
  6. Removed and re-added the domain in Netlify’s dashboard
  7. Clicked “Renew certificate” repeatedly over several days — no change to the “Updated” timestamp

DNS provider: GoDaddy (using GoDaddy nameservers, not Netlify DNS)

Domain verification now shows green/verified in the dashboard, matching www, but the certificate itself won’t renew for the apex. Would appreciate a support engineer taking a manual look — happy to provide any further diagnostics.