Start on your project’s Domains page. An Error card shows the reason, the required DNS records, and Last checked. Use those records as the source of truth for the domain you are fixing.
Check the domain and DNS records
- Confirm that the exact hostname you are opening appears in the project’s domain list.
example.comandwww.example.comare separate names; add and configure each name you intend to use. - At the DNS provider responsible for the domain’s nameservers, compare the record name, type, and value with the records shown in Agiler. The traffic CNAME normally points to
global.agilercdn.net. - Check how your provider expects the record name to be entered. Some DNS editors append the zone name, so entering a full hostname in a field that expects only
wwwcan create a record for the wrong name. - Allow the DNS change to propagate, then click Recheck domain on the error card. You need the Admin or Developer role to manage domains.
For the initial setup steps, see Connect a custom domain.
Provisioning or rechecking
Provisioning means the domain is pending or being checked. Agiler checks DNS and provisions the HTTPS certificate automatically. DNS changes and certificate issuance are separate steps, so a saved DNS record does not immediately mean HTTPS is ready.
After you click Recheck domain, the button spins while the check runs. The previous error can remain visible until the new result arrives. Wait for the check to finish and compare Last checked before treating the displayed error as a new failure.
Resolve the reported error
| Error | What to check or do |
|---|---|
| Nameservers not found | Confirm that the domain is registered and delegated to your DNS provider’s nameservers. Add the required records at that provider. |
| DNS record not found | Create or correct the traffic record for the exact name shown. For a wildcard, check the wildcard traffic CNAME as well as the certificate-validation record. |
| Certificate validation record not found | Create or correct the wildcard’s Certificate validation CNAME, using its exact name and value from Agiler. Keep the traffic CNAME in place too. |
| Traffic not reaching Agiler | DNS resolves, but Agiler’s HTTP check is not succeeding. Verify the traffic target and disable any proxy that prevents requests to /.well-known/acme-challenge/ from reaching Agiler. |
| CAA policy rejected issuance | Review the domain’s CAA policy and update it to permit Let’s Encrypt. Keep the required DNS records configured, then recheck. |
| Certificate authority rate limit | Leave the DNS records in place and retry after the certificate authority’s rate-limit window has passed. Repeated rechecks do not remove that limit. |
| Domain authorization failed | Verify the required records. For an exact hostname, HTTP challenge traffic must reach Agiler; for a wildcard, verify the certificate-validation CNAME. |
| Certificate issuance failed | The certificate authority could not finish issuing the certificate. Keep the required records configured and recheck; contact support if it continues. |
| Certificate validation failed | Agiler could not validate the issued certificate. Keep the required records configured and recheck; contact support if it continues. |
| Internal certificate error | Verify the required DNS configuration and recheck. Contact support if the error persists. |
Wildcard domains
A wildcard such as *.example.com requires both CNAME records shown under Configure wildcard DNS: one for traffic and one for certificate validation. Keep both configured after HTTPS starts working so Agiler can renew the certificate.
The wildcard covers a single subdomain level, such as shop.example.com. It does not cover example.com or a.shop.example.com. Add those names separately if you need them. Wildcard names must use the form *.example.com; embedded or multiple wildcards are not supported.
A wildcard cannot be the Site Domain. Add an exact hostname and use Set as site domain on that entry.
HTTPS works, but the site or URL is wrong
Confirm that the hostname belongs to the intended project. DNS pointing at Agiler is only part of setup: Agiler also uses its project domain assignments to route requests. An exact hostname assignment takes precedence over a matching wildcard, so check for an exact entry on another project if a wildcard hostname loads unexpected content.
Check which entry is marked Site Domain. Agiler passes that name to the application as its server name; the standard single-site WordPress configuration uses it for the site URL. If WordPress generates links to an unexpected hostname, select the intended exact hostname with Set as site domain after configuring its DNS and HTTPS.
For a WordPress multisite network, also check the addresses stored in WordPress and the network configuration in wp-config.php. Multisite uses each site’s configured address instead of Agiler’s single-site URL defaults.
Get help
Contact us if provisioning does not complete, the same certificate error persists after correcting DNS and rechecking, or the domain still serves unexpected content. Include the project name, affected hostname, error text, Last checked time, and the DNS record names, types, and values you configured. For a browser HTTPS error, include the exact URL and browser error message too.