Synthetic Industry

Job builder-custom-domain-certificate-not-issued · revised 11 October 2026

Get your own domain connected and its HTTPS certificate issued on your site builder

Your domain opens your Webflow, Squarespace or Wix site over HTTPS with no warning, using a list of the records to keep and remove, and your email records left unchanged.

You might be seeing

  • The builder's domain panel stays on pending, error or records not found
  • Visitors see a not-secure warning, a certificate error or a different site on your address
  • The site works on the builder's own address but not on your domain

No passwords, keys, card details or admin invites needed to start.

What usually happened

A builder issues the HTTPS certificate only after your domain points at it, and the usual blockers are old records that conflict with the new ones, a certificate-authority restriction at the DNS host, a proxy or protection setting in front of the domain, or a nameserver choice that hides the records you edited. The panel message names the symptom, not the record that causes it.

Who it’s for: Owner of a site on Webflow, Squarespace or Wix whose own domain is stuck on connecting or shows a security warning.

Usually starts when: You connected your domain days ago and the builder still says it is pending or in error, or visitors see a not-secure warning on your own address.

The result: Your domain, with and without www, opens the site over HTTPS with a valid certificate, the builder shows it as connected, and your email records are identical before and after.

Check whether this job fits

Answer these without sending registrar logins. Nothing is submitted unless you choose to contact us.

Can you or someone you know open the page where your domain's DNS records are edited?
Is the domain behind Cloudflare's proxy or another protection layer?
Does your business email use this domain?
How long ago did you last change the domain records?

Answer the questions to see whether this job fits.

Nothing is sent anywhere until you choose to email us.

Send an enquiry about this outcome

Checks you can run yourself

  1. Compare the panel with the DNS list

    Open the builder's domain panel and your DNS host's record list side by side and write down each record the panel asks for next to what exists.

    Look for: Extra records for the same name, a wrong value, or records that exist only in a place the domain does not use are the usual causes.

What you get

  • A before and after list of the DNS records with every change explained
  • The diagnosis of why the certificate was not issued
  • A test record from two networks showing HTTPS on both addresses

Included

  • One domain on one Webflow, Squarespace or Wix site
  • A missing or wrong record for the bare domain or for www on a site the builder hosts; the same fault on a site hosted elsewhere is a different job
  • Reading the DNS records at your DNS host and comparing them with what the builder says it needs
  • An exact change list covering records to add, change and remove, with email records marked do not touch
  • Checks after the change: builder status, HTTPS on both addresses and a before and after record comparison

Not included

  • Moving your DNS hosting or domain registration to another provider
  • Setting up or repairing email, or changing mail records beyond leaving them as they are
  • Making www and the bare address redirect to one version, which is a different job
  • Buying, renewing or transferring the domain
  • A missing bare-domain or www record on a site that is not hosted by the builder; that fault belongs to the DNS job for a site opening on www but not on the bare domain

How we know it’s done

Agreed with you before work starts. Each check produces evidence you keep.

  1. The builder's domain panel shows the domain connected with no required record reported missing.

    Evidence: A screenshot of the panel after the change.

  2. Both the bare domain and the www address open the site over HTTPS with a valid certificate from two different networks.

    Evidence: Browser certificate details for both addresses and the two test locations.

  3. The mail and verification records at the DNS host are identical before and after the change.

    Evidence: The before and after record lists with unchanged records marked.

  4. The browser console on the home page shows no mixed-content warning.

    Evidence: A console screenshot of the home page after the change.

Sign-off. You open both addresses yourself, check the padlock and send a test email to the domain, then sign off before payment.

If it fails. If the agreed checks fail, you do not pay for this fixed scope. We hand over the findings and agree whether to stop or re-quote; no surprise work.

When it fits, and when we stop

It fits when

  • You or your administrator can edit DNS records at the place that hosts them, or can act on our written list
  • The site is published on a plan that allows a custom domain
  • The domain is not already connected to another site of the same builder, or you can disconnect it

We stop and tell you if

  • The domain is controlled by someone who will not act, or the registrar account cannot be recovered
  • The DNS host cannot return a clean reply to certificate-authority queries and will not change that
  • The domain is held or locked at the registry, so records cannot be changed

What could go wrong

The before list of records is kept in the handover, so each deleted or changed record can be restored exactly. Nothing is deleted without your written approval.

Scroll the table sideways to read it all.

RiskHow we handle it
Removing a record that email or another service depends on.Mail and unrelated records are marked do not touch, and every deletion needs your written approval.
DNS changes take hours to show, so a fault looks unfixed.We wait the builder's stated time and test from two networks before reporting a result.
The site is briefly unreachable while records change.We agree a quiet time and keep the old records in the handover so the change can be reversed.
Switching a proxy off removes protections you set up, such as a firewall.A proxy change is listed as a decision for you in the change list; nothing is switched off without your written approval.

An independent reviewer checks the redacted before and after evidence, the list of changes and the way back, and looks separately at anything that touches customer data, payments or logins, before you see the result.

How we deliver

We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.

  • Agree the domain, the builder and who edits the DNS records
  • Record the starting state: the builder's panel, the DNS record list and what each address returns
  • Compare against the builder's required records and the certificate-authority, proxy and nameserver causes in its documentation (on Webflow a CAA record must allow both Let's Encrypt and Google Trust Services)
  • Write the exact change list with email records marked do not touch, and have the agreed person make the changes
  • Wait the builder's stated propagation time, then check status and HTTPS from two networks
  • Have a separate reviewer compare the before and after record lists, then hand over the record and the steps to undo it

This is a one-off job, not emergency cover or a subscription. We confirm eligibility, the total price, a start window and a delivery date before you accept. Work starts only after agreed inputs, secure access and necessary permissions are in place. Builder plan, app, domain and payment-provider charges are yours and are excluded unless the written quote includes them. No charge or booking is created by an enquiry.

Need to keep it working?

If you plan to move DNS hosting or fix email records, those are separate jobs with their own checks.

Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.

Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.

What you can check

This is a new service. We have not delivered this job for a client yet.

Other ways to get this done

  • The builder's own SSL and domain troubleshooting article is a good first step and costs nothing. support.squarespace.com
  • If your certificate used to work and has expired on a host you manage yourself, your host can usually reissue it; that is a different job from a builder domain that never connected.

Questions

Will my email stop working?

Not if we do the job as scoped. Mail records are left alone and compared before and after.

Can you force the certificate to issue?

No. The builder issues it once your domain is eligible. We remove what blocks it and check the result.

Do you need my registrar login?

No. You or your administrator make the changes from our written list, unless you agree a separate narrow arrangement in writing.

Send an enquiry

Send us

  • The domain name, the builder, and a screenshot of the builder's domain panel
  • Where the domain is registered and where its DNS records are edited, if known
  • Whether you use Cloudflare or another proxy, and whether email works on this domain

Later, once you agree

  • A screenshot of the builder's domain panel, or, if you prefer us to read it live, builder access at the role named in the access section, set up by you and removable at any time
  • A screenshot or export of the DNS record list at your DNS host, which you create
  • Agreement on who makes the record changes: you, or someone with registrar access under a written, narrow arrangement
  • A note of any records you know must be kept, such as those for email or other services

You keep the live site, the builder account, the domain and all customer data. Access is agreed with you in writing before any work starts, and no work starts until it is. Any access we use is through a company-controlled account, never a personal login. This job can run without any builder access: you send a screenshot of the builder's domain panel and your DNS record list, and you or your administrator make the record changes from our written list. If you would rather we read the domain panel ourselves, the role depends on the builder. Webflow: the Site manager role, which Webflow describes as managing all site settings, on a paid full seat in your Workspace (or a guest invitation, which Webflow allows only to a Freelancer or Agency Workspace). Squarespace: the Administrator permission, because only owners and administrators can manage domains. Wix: the site owner, or the Domain Manager role, which Wix says can connect and manage domains; Wix's Admin (Co-Owner) role cannot connect a domain. We name the exact role and any seat or plan charge in the quote before you invite anyone; those charges are yours. You can remove our access at any time. No passwords or payment details go by ordinary email, and your authorised account holder publishes the final change.

A public HTTPS link only, without login details, query strings or fragments. No code or logs.

Sending emails your enquiry and contact address to our team through our mail provider (Resend). It is not kept in a website database. Do not send passwords, keys, recovery links, confidential code or customer records. Your contact email is unverified; nothing is ordered, charged or reserved. Privacy notice.

Email fallback: open your mail app

If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “builder-custom-domain-certificate-not-issued” as the subject.