Why it happens
Auto-renewal failed. A DNS record moved, a CAA record forbids the issuer, or the domain is proxied in a way the host's renewal cannot verify.
How to tell
- The newest certificate issued for the domain expires inside fourteen days.
- The host's domain page shows renewal pending or failed.
- A recent DNS change.
The fix
- Open the domain in the host and retry the certificate.
- Check that DNS points where the host expects, and that no CAA record blocks the issuer.
- If the domain is proxied through Cloudflare, use its certificate or set the mode the host documents.
The prompt for your builder
Paste this into Lovable, Bolt, Cursor, Claude Code or whatever built the app. Replace anything in capitals. It never asks you to paste a secret into a chat; keys go into your host’s environment, by you.
My site's TLS certificate is not auto-renewing on HOST. Tell me the DNS records HOST expects for my domain, how to check for a CAA record that would block issuance, and the exact steps to trigger a renewal.
How Keelnest catches it
Once a day Keelnest reads the newest certificate issued for your domain from the public certificate logs, and opens an incident at fourteen days left (Critical at seven) while there is still time to act. It resolves itself when a renewal appears in the logs, and a certificate that actually lapses fails the five-minute site check on its own.
Know the moment this happens.
Keelnest watches your production app every five minutes and tells you in plain English what broke — with the fix. Free for your first app.