Issue while renewing SSL certificate

Getting following error while renewing the SSL certificate:

This is my AWS Route53 config:

I don’t know what value it is expecting in the TXT DNS record so I have set a default value as ‘key=value’


*SniCertificate::CertificateInvalidError: Unable to verify challenge for Incorrect TXT record "key=value" found at 

We can’t renew your Let’s Encrypt certificate automatically until the issue is resolved. Check our troubleshooting guide for more information on how to fix the problem, and then renew the certificate.

@furiabhavesh Did you recently make changes to your DNS settings? I ask because you seem to have two different DNS set-ups currently active – one of which will NOT allow Netlify to issue an SSL certificate. For example:

|===================== whois name server for ====================
| ---------------------- ----------------------
Updated Date: 2020-08-22T16:34:06.710Z
Name Server:
Name Server:
Name Server:
Name Server:


|===================== dig name server(s) for ===================
| ---------------------- ----------------------
| ------------------- should agree with whois -------------------

As a result, you are showing an inactive DNS zone:

|================== check for inactive DNS zone =================
| --------------- last line should show ---------------
| ----------------- for sites using Netlify DNS -----------------
| ---------------- otherwise will show DNS source ---------------
| ---------------------- ----------------------	172800	IN	NS	172800	IN	NS	172800	IN	NS	172800	IN	NS
;; Received 134 bytes from in 25 ms

See the documentation here:

Once you get your DNS straightened out and fully propagated, your certificate should be renewed or at least renewable.

1 Like

I don’t know from where the following values are coming from ? I had them previously but I removed them long time back.

Name Server:
Name Server:
Name Server:
Name Server:

That’s why I also posted my Route53 Config.

Is it possible that these are cached somewhere ?

@furiabhavesh If you haven’t made a change since August 2020, they are almost certain still live entries. DNS changes typically take 48 hours or less to propagate.


So what do you recommend I should do now ?

Delete the existing hosted zone in Route53 and create a fresh one ?

@furiabhavesh The first thing to do is re-read the docs about this.

You have made “name server” entries in AWS instead of delegating DNS to Netlify. You have to pick one or the other – either use AWS as external DNS or delegate to Netlify. Your mixed set-up is never going to work.