AutoSSL Not Issuing or Renewing SSL Certificates

Estimated reading: 5 minutes

AutoSSL makes it easy to secure your website by automatically issuing and renewing SSL certificates. If AutoSSL fails, your website may display security warnings, lose the HTTPS padlock, or show certificate errors to visitors.

In most cases, AutoSSL issues are caused by DNS misconfigurations, firewall restrictions, invalid domain settings, or domain validation failures. This guide will help you identify the problem and get your SSL certificate issued or renewed successfully.

Common Symptoms

If AutoSSL isn’t working properly, you may notice one or more of the following:

  • Your website displays “Your connection is not private.”
  • The SSL certificate has expired.
  • HTTPS is no longer working.
  • AutoSSL reports one or more domain validation failures.
  • New domains don’t receive an SSL certificate.
  • The browser displays a certificate warning.
  • Mixed content warnings appear after installing SSL.
  • The AutoSSL status shows Pending, Failed, or Expired.

Common Causes

AutoSSL failures are usually caused by one of the following:

  • Incorrect DNS records.
  • The domain doesn’t point to the hosting server.
  • Recent DNS changes haven’t propagated yet.
  • Firewall or security rules blocking validation requests.
  • Invalid or conflicting DNS records.
  • The domain or subdomain has been removed from the hosting account.
  • Existing SSL certificates conflicting with AutoSSL.
  • Temporary validation service issues.

Solution 1: Verify Your Domain’s DNS Records

AutoSSL can only validate domains that point to the correct hosting server.

Check that:

  • Your domain uses the correct nameservers.
  • Your A record points to your hosting account’s IP address.
  • Your AAAA record (if used) points to the correct IPv6 address.
  • There are no outdated DNS records pointing elsewhere.

If you’ve recently updated your DNS, allow time for the changes to propagate before requesting a new certificate.

Solution 2: Confirm the Domain Is Added to Your Hosting Account

AutoSSL only issues certificates for domains that exist within your cPanel account.

Verify that the affected domain has been added as:

  • Your primary domain.
  • An addon domain.
  • A subdomain.
  • A parked (alias) domain.

If the domain isn’t listed in your account, add it before attempting to issue an SSL certificate.

Solution 3: Check for DNS Propagation

If you’ve recently changed your nameservers or DNS records, the changes may still be propagating across the internet.

During this period, AutoSSL validation may fail because different DNS servers are returning different results.

DNS propagation typically completes within a few hours, although in some cases it may take up to 48 hours.

Solution 4: Remove Conflicting DNS Records

Incorrect DNS records can interfere with domain validation.

Review your DNS zone for:

  • Incorrect A records.
  • Old AAAA records.
  • Conflicting CNAME records.
  • Duplicate DNS entries.

Once corrected, wait for DNS propagation before trying AutoSSL again.

Solution 5: Verify Your Website Is Publicly Accessible

AutoSSL must be able to reach your website during the validation process.

Open your domain in a browser and verify that:

  • The website loads normally.
  • There are no maintenance pages.
  • The domain doesn’t redirect to an invalid destination.
  • The server responds without errors.

If the website is inaccessible, resolve that issue first before requesting an SSL certificate.

Solution 6: Check for Firewall or Security Restrictions

Security software may accidentally block AutoSSL validation requests.

If you’re using:

  • Cloudflare
  • ModSecurity
  • A Web Application Firewall (WAF)
  • Security plugins

ensure they aren’t blocking validation traffic.

If necessary, temporarily disable aggressive security rules and try running AutoSSL again.

Solution 7: Remove Expired or Invalid SSL Certificates

In some cases, manually installed or expired certificates may interfere with AutoSSL.

If you previously installed a custom SSL certificate, it may need to be removed before AutoSSL can issue a replacement.

If you’re unsure, our support team can safely verify your SSL configuration.

Solution 8: Run AutoSSL Again

After correcting any DNS or configuration issues, run AutoSSL again.

Within cPanel:

  1. Open SSL/TLS Status.
  2. Select the affected domain.
  3. Click Run AutoSSL.

The validation process may take several minutes to complete.

Solution 9: Verify HTTPS After Installation

Once the certificate has been issued successfully:

  • Visit your website using https://.
  • Confirm the browser displays a secure padlock.
  • Check that there are no certificate warnings.
  • Verify all subdomains are also secured, if applicable.

If your website still displays Not Secure, the issue may be related to mixed content rather than the SSL certificate itself.

Solution 10: Contact VeerHost Support

If AutoSSL still fails after following the steps above, our support team is happy to help.

We’ll investigate your hosting account and verify:

  • AutoSSL service status.
  • Domain validation errors.
  • DNS configuration.
  • SSL certificate conflicts.
  • Firewall or server restrictions.
  • Domain accessibility.

To help us troubleshoot more efficiently, please include:

  • The affected domain name.
  • A screenshot of the AutoSSL error (if available).
  • Any recent DNS or nameserver changes you’ve made.
  • The approximate time the issue occurred.

Our team will review your configuration and work to restore your SSL certificate as quickly as possible.

Best Practices

Following these recommendations can help prevent future AutoSSL issues:

  • Keep your DNS records accurate and up to date.
  • Avoid unnecessary DNS changes.
  • Allow DNS changes to fully propagate before requesting an SSL certificate.
  • Regularly verify that your domain points to the correct hosting server.
  • Remove unused or outdated DNS records.
  • Monitor your SSL certificate before it expires.
  • Test your website over HTTPS after making DNS or hosting changes.
  • Contact our support team if you’re unsure about modifying your DNS settings.

By following these best practices, you can ensure your SSL certificates renew successfully and keep your website secure for both visitors and search engines.

Launchpad