CuCustom domain SSL won’t provision for fishcity.app (Cloudflare DNS)

Hi Netlify team,

I’m having trouble getting SSL to provision for my domain fishcity.app. My site is eloquent-florentine-245bf2. I am using Cloudflare DNS with:

A records for @:

  • 75.2.70.75
  • 99.83.190.102

CNAME for www:

  • eloquent-florentine-245bf2.netlify.app

Proxy status is DNS only. DNSChecker shows correct propagation worldwide. I have retried DNS verification several times and waited over 2 hours. Could you please force an SSL/certificate re-check for my custom domain? Thank you!

@fishcity If you received those A records from an AI, then you’ve been mislead (like many others):

Remove the A record from both Netlify and Cloudflare?

@fishcity What do you even mean by that?

Are you suggesting you have DNS records in two places?

I have DNS record on cloudflare and then the DNS record i put on Netlify.

@fishcity If your nameservers are set to cloudflare (which they are), then you aren’t using Netlify DNS.

If you’re for some reason trying to also manage them somewhere they aren’t being used, then I suppose you could keep those up to date too, but it’s your choice.

I was trying to use the cloudflare domain…but looks like i got confused. I set up those two A records, then I put two A records and a CNAME on cloudflare.

Sorry for the trouble…what’s the best practice here to host on Cloudflare? Or what’s the simplest path forward..

@fishcity You can have your DNS records be wherever you would like, it’s personal preference.

I’m not going to push you one way or the other, I don’t even work for Netlify.

Netlify have some documentation/marketing on the benefits of their system here:
https://docs.netlify.com/domains/why-netlify-dns/#netlify-dns-key-benefits

One downside to using it, is if you’re on the ‘Free’ plan, and you go over any limit, for example ‘bandwidth’, then they’ll disable your DNS too for the remainder of the month, and your email MX records may stop working etc.

Yea…I got the dns to be verify, just waiting for it to post now. However it does say SSL_Protocol_error