Site name (Netlify): garyphillip
Primary domain: nottingham-wedding-photographer.com (working fine, current cert expires Aug 6, 2026)
Domain alias: garyphillip.co.uk (currently showing “not secure” to visitors, not included on the active certificate at all)
Error shown in Domain management > HTTPS:
SniCertificate::CertificateValidationError: Unable to verify challenge for *.garyphillip.co.uk: DNS problem: NXDOMAIN looking up TXT for _acme-challenge.garyphillip.co.uk
I have never configured a wildcard domain. I only need standard hostnames for the primary domain and the alias domain, both with and without the www prefix.
The alias domain’s DNS is hosted externally at Cloudflare (not Netlify DNS), which is why Netlify can’t write the wildcard validation TXT record itself.
I’ve already corrected the Cloudflare proxy setting for the alias domain (was Proxied, now DNS only), but the wildcard challenge still fails and the “Renew certificate” button is gone from my HTTPS panel (only “Set custom certificate” shows).
Please clear the stuck wildcard certificate state and issue a standard (non-wildcard) certificate covering all four hostnames. This is time-sensitive since the current certificate expires 6 Aug 2026.