External DNS: Let's Encrypt cert won't provision despite Let's Debug 'All OK' - site auvisoweb / auviso.com

Hi Netlify Support,

I’m unable to provision a Let’s Encrypt certificate for my custom domain, even though all DNS checks pass and Let’s Debug reports “All OK” for both hostnames. This looks like a stuck provisioning order / rate-limited ACME state on your side rather than a DNS misconfiguration.

Site / domain

  • Netlify site: auvisoweb (auvisoweb.netlify.app)
  • Custom domain: auviso.com (primary), www.auviso.com (redirect to primary)
  • DNS type: External DNS, hosted at Artfiles (nameservers auth1.artfiles.de / auth2.artfiles.de)

Current DNS configuration (verified correct)

  • Apex A record: auviso.com75.2.60.5 only (the old second load-balancer IP 99.83.190.102 has been removed; single A record)
  • www CNAME: www.auviso.comauvisoweb.netlify.app
  • DNSSEC: disabled at registrar
  • AAAA records: none
  • CAA records: none

Let’s Debug - both hostnames return “All OK” (http-01):
https://letsdebug.net/auviso.com/3029587
https://letsdebug.net/www.auviso.com/3029589

Dashboard error (Domain management > HTTPS)
“We could not provision a Let’s Encrypt certificate for your custom domain.” / “This step cannot be completed unless the DNS records for your custom domain are already pointing at our servers.” - but the records do point to your servers, as confirmed above and by Let’s Debug.

Troubleshooting already completed

  1. Deleted a leftover Netlify DNS zone for the domain that was stuck on “Netlify DNS propagating…” - the domain then correctly switched to External DNS and passed “DNS verification was successful.”
  2. Removed the duplicate apex A record so only 75.2.60.5 remains.
  3. Confirmed global propagation (apex resolves to 75.2.60.5 only; www resolves via CNAME to the Netlify edge).
  4. Ran Let’s Debug for both hostnames - both “All OK” (links above).
  5. Removed the custom domain, waited, and re-added it as External DNS - certificate still fails to provision.
  6. Stopped manual retries to avoid adding to the failed-validation rate limit.

Request
Since Let’s Debug confirms both names are fully validatable right now, could you please check the certificate provisioning logs on your end and surface the actual Let’s Encrypt error, then manually trigger issuance / clear the stuck order for this site? If there is an account-level ACME rate limit from the earlier failed attempts, please advise how long until it clears.

Happy to provide the team ID or any further details privately if needed. Thanks very much for your help!

may i get an answer please

Please, no advertising.

Still no answer from NETLIFY???

Hey @Rene_Fleischer :wave:,
Thanks for reaching out!

We’ve gone ahead and created a support ticket for you, so our team can follow up with you directly via email from the help desk. Our Support crew will be in touch with you by email soon.

Great news: these days anyone can reach out to Netlify Support. First, you can try getting an answer using Ask Netlify, our helpful AI search tool. If your question isn’t answered there, you can submit a ticket using the support form, and we’ll take it from there.

We’re keeping the community around for swapping ideas, sharing tips and tricks, and talking shop with other folks building on the platform — but for support issues, tickets are the way to go.

Thanks for being here, and keep an eye out for that email from us!