A certificate warning on your domain
Work down this list in order. It is sorted by how often each cause turns out to be the real one, and the first two account for nearly all of them. If the hostname does not resolve at all yet, a record will not verify is the page to start on instead.
The state of each hostname is in the HTTPS card on the domain tab, in Settings, then Domain and DNS. Read that card before changing anything: it names the hostname that is failing, which narrows this from three possible records to one.
Is the record for that hostname still proxied through Cloudflare?
On Cloudflare, a proxied record can put a hostname into exactly this state: the DNS table goes green and the certificate never issues.
That happens because a proxied hostname answers with Cloudflare’s addresses, and Issue Mint accepts an address answer for the website and tracking records, since plenty of providers legitimately flatten those. So the row verifies, traffic arrives, and the certificate behind it cannot be validated. Open the record in Cloudflare, click the cloud until it is grey rather than orange, save, and press Verify now.
Has the certificate record for that exact hostname verified?
The certificate records are per hostname, so www can be secure while the bare domain
warns, or the other way round.
Three of them exist, one for each hostname Issue Mint serves: _acme-challenge for the
bare domain, _acme-challenge.www, and _acme-challenge.go for the tracking hostname
that carries the links in your issues. Find the row matching the hostname in the
browser warning and check that one rather than reading the table as a set. The values
carry an identifier that only exists inside your account, so copy each one from the
domain tab with the button beside it rather than typing it.
Has it been more than a few minutes?
Certificates are issued asynchronously, and minutes is normal. A row saying it is waiting for the certificate, shortly after the records went in, is the expected state rather than a fault.
Issue Mint re-reads Cloudflare after every verification pass, so one press of Verify now updates the records and the certificates together. A hostname still waiting an hour later is worth looking at, and its own certificate record is almost always why.
Is the certificate record coming back as addresses?
A certificate record must resolve as a real CNAME. If your provider answers it with addresses instead, it cannot work, and the record row says so by printing what it found underneath what it expected.
The reason is that Cloudflare has to follow that CNAME itself in order to renew, which is the opposite of the website records, where an address answer is fine. How certificates work here covers what the delegation actually does. In practice this shows up on providers that flatten every CNAME in the zone rather than only the ones at the root.
Is it the bare domain on a newsletter using the www address?
One row of the HTTPS card stays on waiting for ever on a www domain, and that is
expected rather than broken.
A certificate cannot be issued for a hostname that does not resolve, and the whole
reason a newsletter moves to www is that the bare domain could not be pointed here.
Nothing a reader touches is affected: your website, your archive and
the tracking links in your issues all run on hostnames that
do resolve. If you did not choose that address deliberately,
the bare domain will not verify explains
when Issue Mint offers it.
Does the card quote an error rather than saying it is waiting?
When Cloudflare reports an actual problem, Issue Mint prints Cloudflare’s own wording rather than paraphrasing it.
Their message names the specific failure, and you are the person who has to act on it,
so a rewrite of it here would only add a translation step. The one that comes up most
says validation timed out and tells you to check the _acme-challenge record for that
hostname, which means the record is not answering: it was never added, it was added on
the wrong host, or it has been deleted since.
Still stuck
Write to us with the hostname from the browser warning and we will look at what Cloudflare is telling us about it.
There is one cause you cannot see from your side and we can: a hostname already claimed on another Cloudflare account cannot be issued a certificate for us, however correct your records are. Issue Mint raises an alert internally when a hostname never gets that far, so this is worth asking about rather than re-checking a record that will never change anything.
Questions
Does a certificate warning affect my emails?
Not the sending itself. The records that authorise mail from your domain are separate from the certificate records, and neither depends on the other. It does affect readers, though: the links inside your issues run on go.yourdomain.com, so a warning on that hostname is one your subscribers meet when they click.
Can this happen on my issuemint.com address?
No. Every newsletter's slug.issuemint.com address has HTTPS from the moment the newsletter is created, with no records to add and no certificate records involved, which is also why it is worth leaving in place while a custom domain settles.
Try it on your own list.
14 days, every feature, no card. Sending works from the moment you sign up.
Start your trial