Provider repair guideReviewed 2026-08-07By HostWithShery technical editorial

Fix Netlify HTTPS certificate pending

Correct DNS first, then allow certificate provisioning to complete.

Start with evidence from your own domain before changing DNS, SSL or mail settings.
Check your own configuration

SSL Certificate Checker

This page is preconfigured with the SSL Certificate Checker that best matches this problem.

No accountPublic evidence only
Live public check
No account · Public configuration only
On this page

Fix Netlify HTTPS certificate pending: when this repair path applies

Correct DNS first, then allow certificate provisioning to complete. Use these steps when DNS is not yet in a state where Netlify can provision the certificate, but first run the embedded diagnostic so the TLS, certificate and HTTPS evidence supports this provider-specific path rather than a neighboring DNS, TLS, application or mail cause.

Find the authoritative setting before editing

Netlify Domain management/DNS together with the external registrar or DNS provider when Netlify DNS is not authoritative. For Fix Netlify HTTPS certificate pending, confirm the active nameservers and exact service owner before changing verify authoritative DNS. A DNS-looking screen at netlify has no public effect when another provider is authoritative for the zone.

Evidence to save for Fix Netlify HTTPS certificate pending

Record the current public state for verify authoritative DNS, check both root and www, remove stale conflicting records. This gives the repair a before/after comparison and prevents a cached answer or a separate working service from being confused with the configuration that produced the symptom.

  • Verify authoritative DNSQuery the authoritative servers directly and compare their answers. This separates a stale recursive cache from inconsistent source DNS data.
  • Check both root and wwwVerify check both root and www from the public Internet and compare it with the value the responsible provider says should be live.
  • Remove stale conflicting recordsVerify remove stale conflicting records from the public Internet and compare it with the value the responsible provider says should be live.
  • Retest HTTPSRecord the public status, final URL and relevant response headers. A working DNS answer does not prove that the application is serving a genuine website response.

Repair steps in netlify

Correct DNS first, then allow certificate provisioning to complete.

  • 1. Verify authoritative DNS. After this step, check the public value tied to verify authoritative dns before changing another unrelated setting.
  • 2. Check both root and www. After this step, check the public value tied to check both root and www before changing another unrelated setting.
  • 3. Remove stale conflicting records. After this step, check the public value tied to remove stale conflicting records before changing another unrelated setting.
  • 4. Retest HTTPS. After this step, check the public value tied to retest https before changing another unrelated setting.

Why this order matters for netlify

The sequence begins with the provider/authority decision, then moves through verify authoritative DNS, check both root and www, remove stale conflicting records. That keeps the change scoped to the failed TLS, certificate and HTTPS path and avoids replacing nameservers, mail authentication or another healthy service just to make a provider dashboard indicator change.

Verify Fix Netlify HTTPS certificate pending

HTTPS should complete for the exact hostname, the certificate should be valid for that hostname, and root/www should follow the intended canonical redirect without a TLS error. Compare the same verify authoritative DNS and check both root and www evidence used before the change; a repair is complete when the public result agrees, not merely when the netlify interface reports that a save succeeded.

If netlify and the public result disagree

Check whether the edited zone is authoritative, whether the exact root/www/subdomain was changed, whether a proxy state alters the visible endpoint, and whether a prior TTL can still exist in recursive caches. Do not add a second conflicting verify authoritative DNS value to force validation.

Mistakes to avoid for this repair

Do not copy tenant-specific or region-specific values from another account, delete working email records during a website repair, change nameservers as a shortcut, or alter SSL/proxy modes without evidence from the origin. Fix Netlify HTTPS certificate pending should change only the settings required by this diagnosis.

Technical references

These primary standards and provider documents are used to verify the behavior described on this page. Provider dashboards can change, so use the current official value for tenant-specific DNS records rather than copying an example from another account.