Browse the documentation

HTTPS on a custom domain

Every hostname Issue Mint serves on your domain gets its own HTTPS certificate, issued and renewed for you. There is nothing to buy, nothing to upload and no expiry date to write in a calendar.

Three hostnames are involved: your website on the bare domain, the same site on www, and go.yourdomain.com, which serves the tracking links inside your issues. The tracking hostname matters as much as the other two, because it is the one a reader meets by clicking a link in an email, where a browser warning does the most damage.

Where the certificate comes from

Cloudflare issues it. Your DNS points the website at sites.issuemint.com, HTTPS is terminated at Cloudflare’s edge, and no customer ever points a record at a raw IP address, which is what makes it possible for us to change infrastructure without asking every publisher to go and edit DNS.

The practical consequence is that certificates are not on your list of things to do. Adding the records described on the records page is the whole of your part.

What the certificate records actually delegate

The three _acme-challenge records hand Cloudflare permission to prove the hostname is yours, once, for as long as the record stays there.

Each one is a CNAME pointing at a per-zone target, which is why the value cannot be printed in documentation and has to be copied from your domain tab. The alternative approach, which plenty of platforms use, is a fresh TXT record at every renewal. That works exactly until the person who set it up moves on, and then the site goes dark ninety days later. Delegation is what makes renewals silent instead.

Why a hostname that resolves can still show a warning

Because pointing a hostname at Issue Mint and proving it is yours are two different records, and they can be in different states.

A hostname whose website record has verified is routing traffic to us. If its certificate record has not verified, no certificate can issue for it, and a browser arriving at a hostname that answers over HTTPS without a valid certificate shows a warning rather than your site. That is worse than being down: an outage looks like an outage, and a certificate error looks like something has been hijacked. It is also why the certificate records must not be proxied or flattened, unlike the website records. Cloudflare has to follow those CNAMEs itself.

What the HTTPS card tells you

The domain tab shows one row per hostname, separately from the DNS table, because a certificate is not something you add. It is something that happens because you added a record.

A row says Secure only when both halves are live: the hostname is routing traffic and its certificate is valid. Until then it says it is waiting, which is the normal state for the first few minutes. When Cloudflare reports an actual problem, Issue Mint prints Cloudflare’s own wording rather than paraphrasing it, because their message names the specific failure and you are the person who has to act on it. The card is re-read after every verification pass, so one press of Verify now updates the records and the certificates together.

Renewals, and the one way they break

Renewal is automatic and silent, for as long as the certificate records stay where you put them.

The one way to break it is to delete or edit those records later, during a DNS tidy-up or a move to a new provider. Issue Mint re-checks a verified domain daily and emails you when a record it relies on disappears, so this surfaces as an email rather than as a reader telling you your site looks unsafe. Leaving the three _acme-challenge records alone for ever is the whole maintenance story.

What this does not cover

Your free {slug}.issuemint.com address already has HTTPS and always did, with no records and no certificate records involved. Your free address explains what else runs there.

Issue Mint also issues certificates only for the three hostnames above. Other subdomains of your domain are yours to serve however you like, and nothing here touches them or the mail records that let you send from your own address.

Questions

How long should a certificate take?

Minutes, usually. Issuance is asynchronous, so a row that says it is waiting is normal for a short while after the records go in. A row still waiting an hour later is worth looking at, and the certificate record for that specific hostname is almost always the reason.

Can I supply my own certificate?

No. There is nowhere in Issue Mint to upload a certificate or a private key, and no setting for a certificate authority you would rather use. Certificates are issued for you, on the hostnames Issue Mint serves, and renewed without asking.

On the product side: what the archive website gives you.

Last updated 21 August 2026.

Try it on your own list.

14 days, every feature, no card. Sending works from the moment you sign up.

Start your trial