Synthetic Industry

Troubleshooting guide · updated 2026-10-11

Custom domain stuck on pending or showing a security warning on Webflow, Squarespace or Wix

A builder issues its HTTPS certificate only once your domain points at it cleanly. The usual blockers are leftover records, a CAA restriction, a proxy in front of the domain, DNSSEC and impatience.

The certificate follows the connection

Every one of the three builders issues the HTTPS certificate for your domain after it can see that the domain points at the builder. If the domain is not pointing correctly, or a restriction stops the certificate authority, the panel shows pending, error or records not found. That is a message about the connection, so the fix is in the DNS records, not in the certificate.

The records you need differ by builder and can change over time, so copy them from your builder's own domain panel rather than from an old article. Wix, for example, lists an A record on the root domain and a CNAME record on www for the pointing method, and says the domain must be connected to your site for the certificate to be enabled. Webflow says a custom domain that still points at its legacy DNS records can no longer be published to, so an older site may need its records changed to the ones shown in its Publishing settings. Squarespace shows each required record in its panel, with a status beside it.

  • Open the domain panel and copy the records it lists.
  • Open your DNS host and compare record by record: name, type and value.
  • Write down which records are for email before you change anything.

Conflicts and leftovers

The most common blocker is a record that should have been replaced and was not. Webflow says extra A records on the root domain conflict with its own, as do duplicate CNAME records. Squarespace shows conflicting records in red and says to delete them, to delete an A record with a blank host, and to keep an A record on a Mail or Email host because it supports email. Typos in a verification record are common too, and some DNS editors append your domain to the value, which Squarespace fixes with a trailing period.

Take care of the other direction: a record that looks unused may carry email or another service. Compare before and after, and change one thing at a time.

  • Remove only records the builder names as conflicting, with the owner's approval.
  • Leave MX, SPF, DKIM and DMARC records as they are.
  • Re-read the panel after each change rather than guessing.

Restrictions in front of the domain

Four things sit between your records and the certificate. A CAA record tells certificate authorities who may issue for your domain: Squarespace says its provider cannot issue if a restriction blocks it, and Webflow says a CAA record must allow both of the authorities it uses, Let's Encrypt and Google Trust Services. A proxy, such as Cloudflare's orange cloud, hides the real records: Wix says the A and CNAME records must be DNS only, and Webflow says a proxied record can cause a 525 handshake error, so it should be DNS only unless you set up Cloudflare's Orange-to-Orange option, which Webflow supports. Turning a proxy off can remove protection you chose, such as a firewall, so that is your decision. DNSSEC can interrupt propagation; Wix asks you to confirm it is not signed for a domain bought elsewhere, and Squarespace cannot guarantee third-party DNSSEC works. Custom nameservers can mean the records you edited are not the ones the domain uses, and Squarespace says to return to the provider's default nameservers if a nameserver connection fails.

None of these is a mistake to be embarrassed about. They are protections that were correct before the site was moved.

  • Look for a CAA record on the domain and read who it allows.
  • Look for an orange cloud beside the website records; on Webflow it must be off unless Orange-to-Orange is set up.
  • Ask whether DNSSEC is switched on at the registrar.
  • Confirm which nameservers the domain really uses.

How long to wait, what does not fit, and acceptance

Squarespace and Wix both say a new connection can take up to 48 hours, and Squarespace asks you to wait 48 hours after any change before testing in a private window. Refreshing repeatedly does not help; Squarespace says to wait 48 hours after your last refresh. If the records are correct and the status is still wrong after about two days, the builder's support is the next step.

A certificate that used to work and has expired, a move of DNS hosting, or mail records that need repair are different jobs. The fixed-scope fix of one domain is priced at £115 as an untested proposal and paid only after you sign off. It is accepted when the builder shows the domain connected, both the bare and www addresses open over HTTPS from two networks, and the mail and verification records are identical before and after.

Sources and limits

  • Squarespace: troubleshooting SSL Checked 2026-10-11.
    • New or recently connected domains need up to 48 hours, and a CAA restriction at the domain provider can stop the certificate being issued.
    • Third-party DNSSEC cannot be guaranteed to work with the certificate set-up.
  • Squarespace: troubleshooting third-party domain connections Checked 2026-10-11.
    • Conflicting records show in red and should be deleted, an A record with a blank host should be deleted, and an A record for Mail or Email should be kept.
    • Nameserver-connect failures after 48 hours are fixed by returning to the provider's default nameservers.
  • Wix: troubleshooting your SSL certificate Checked 2026-10-11.
    • The page lists an A record on the root domain and a CNAME record on www for the pointing method, and says the domain must be connected to the site for the certificate to be enabled.
    • It asks for up to 48 hours of propagation and for DNSSEC not to be signed on a domain bought elsewhere, and warns that http:// code in HTML elements can trigger a not-fully-secure message.
  • Wix: Cloudflare settings for connecting a domain Checked 2026-10-11.
    • The A and CNAME records must be set to DNS only, not proxied.
  • Webflow: configure CAA records for Webflow SSL Checked 2026-10-11.
    • If you use CAA records they must allow both of Webflow's certificate authorities, Let's Encrypt and Google Trust Services, or certificates may fail to provision or renew.
  • Webflow: why does my domain show an error status Checked 2026-10-11.
    • Incorrect nameservers, propagation of up to 48 hours, incorrect DNS records and additional A or CNAME records on the same host are listed causes of an error status, and the exact records for a site are shown in its Publishing settings.
  • Webflow: connect your Cloudflare domain to Webflow Checked 2026-10-11.
    • For standard Webflow hosting the Cloudflare records are set to DNS only, and a 525 handshake error can mean the proxy (orange cloud) is on.
    • Webflow points to Cloudflare Orange-to-Orange as the way to use Cloudflare's proxy features with Webflow hosting.
  • Webflow: update your DNS settings for Webflow's Cloudflare migration Checked 2026-10-11.
    • As of 13 January 2026 you cannot publish to a custom domain that points to Webflow's legacy DNS records, and sites on legacy hosting stay live but cannot be changed until the domain's DNS settings are updated.