SSL certificate setup

SSL certificates are issued and renewed automatically once your domain's DNS is verified, there's no certificate to generate or install yourself. This article covers what you'll see while that happens and what to do if it gets stuck.

How it works

Once your DNS records check out, Cloudflare automatically issues an SSL certificate for your domain. From there, it's also renewed automatically, nothing to schedule or track on your end.

Certificate is being issued

While a certificate is provisioning, you'll see "Certificate is being issued by Cloudflare. This usually takes a few minutes after DNS records are verified." No action is needed here, it resolves on its own.

Typical timing is 2 to 5 minutes after your DNS records are correctly in place, occasionally longer if Cloudflare's issuance queue is backed up. If it's been a while, it's still normal to wait, this stage doesn't require anything from you.

When action is needed

A warning icon appears when a certificate is stuck and something needs fixing at your DNS provider. There are two situations:

CAA records blocking issuance

If your domain has CAA records that don't permit Cloudflare's certificate authorities, add these:

0 issue "letsencrypt.org"
0 issue "pki.goog"
0 issue "letsencrypt.org"
0 issue "pki.goog"
0 issue "letsencrypt.org"
0 issue "pki.goog"

Once added, issuance retries automatically, there's nothing to trigger manually.

An additional TXT record is required

Sometimes Cloudflare needs one more record to validate the certificate, this shows up as a fifth DNS row alongside your regular records (see DNS Setup Guide). Add it at your DNS provider, and the certificate issues automatically once it validates.

Something else

If neither applies and an error message is shown instead, this is rare and usually points to a misconfigured hostname on our end. Contact support@redirect.supply and we'll sort it out.

SSL status is independent of domain status

A domain can show Connected while its SSL certificate is still issuing, or even stuck, these are checked separately. Domain status only reflects DNS records; SSL progress is only visible inside DNS Settings. This is completely normal right after connecting a domain, give the certificate a few minutes to catch up.

HTTP and www, handled for you

Every redirect automatically upgrades HTTP requests to HTTPS and handles www/non-www variants, there's no toggle or setting, it's covered by default so you can just focus on creating the redirect itself.

If a certificate stays stuck

See SSL Certificate Issues for more troubleshooting, or check Domain Statuses to confirm your DNS side is fully verified first.

Missing something?

If there's a feature you need that Redirect Supply doesn't have yet, we want to hear about it. Every request goes straight to the team building this.

Missing something?

If there's a feature you need that Redirect Supply doesn't have yet, we want to hear about it. Every request goes straight to the team building this.

Domains

/

SSL certificate setup