Certificate renewal reports "missing domains" for a domain already on the served certificate

Site: sixagain (sixagainsportsfishing.com)

The HTTPS panel shows: “Certificate renewal incomplete: missing domains sixagainsportsfishing.com. However, the certificate currently being served already includes that domain:

  • subject=CN=sixagainsportsfishing.com
  • SAN: sixagainsportsfishing.com, www.sixagainsportsfishing.com
  • Valid Jul 19 2026 → Oct 17 2026

I’ve verified externally:

  • Apex A75.2.60.5, confirmed identical on both authoritative nameservers (ns53/ns54.domaincontrol.com)
  • No AAAA record on the apex (ruling out IPv6 preference failure)
  • No CAA records on either domain
  • No stale _acme-challenge TXT records
  • http://sixagainsportsfishing.com/.well-known/acme-challenge/ reachable on port 80 and not intercepted by the HTTPS redirect
  • Netlify’s edge correctly recognises the apex Host header (returns 301 → www)
  • Domain settings contain only the 3 expected entries, no stale aliases

The certificate was created Jul 19 11:33 AM and updated 1:12 PM — during my DNS migration, so I suspect the first provisioning attempt failed before the apex A record propagated and the error state persisted after the retry succeeded.

My question: is this a stale error state, or will the automatic renewal genuinely fail in September? I’d prefer not to force a reprovision on a working certificate unless you confirm it’s necessary — please advise before any action that replaces the current cert.