TLS certificate renewal fails: stale _acme-challenge TXT record for *.utopica.net not visible in DNS UI

Site name: utopica (utopica.net)

Problem: The wildcard TLS certificate for *.utopica.net cannot be renewed. Every attempt fails with:

SniCertificate::CertificateValidationError: Unable to verify challenge for *.utopica.net: Incorrect TXT record found at _acme-challenge.utopica.net

What we’ve tried:

  • Checked both Cloudflare and Netlify DNS UI for any _acme-challenge TXT records — none are visible in either interface
  • Netlify DNS is active for utopica.net (nameservers: dns1-4.p03.nsone.net)
  • Every manual “Renew certificate” attempt generates a NEW challenge token, but keeps finding a stale/conflicting TXT record that is not visible or deletable from our end
  • We hit the Let’s Encrypt rate limit (5 failed authorizations in 1 hour) after multiple attempts

Current certificate status:

  • Expires: Jun 19, 2026 (12 days remaining)
  • Domains: *.utopica.net, utopica.net

Conclusion: Netlify’s internal DNS system appears to be leaving stale _acme-challenge records from previous renewal attempts that are not surfaced in the Netlify DNS UI, blocking all future renewals. We need Netlify support to manually clean up these stale records for _acme-challenge.utopica.net.

Please help us resolve this before the certificate expires on June 19.