Objective
Troubleshoot and resolve cases where Auto-SSL Custom Link Branding stays stuck on "SSL Certificate Provisioning" despite CNAME DNS records being verified in the SendGrid Console.
Product
Twilio SendGrid Email
Procedure
When Auto-SSL is enabled, SendGrid uses Cloudflare to manage and issue SSL certificates for your branded link subdomains. Stalled provisioning is typically caused by one of two common DNS misconfigurations.
CAA Restrictions
Certification Authority Authorization (CAA) records specify which Certificate Authorities (CAs) are allowed to issue SSL certificates for your domain. If your CAA records restrict issuance to specific CAs (e.g., GlobalSign or DigiCert) without permitting Cloudflare's CAs, certificate provisioning will fail.
Troubleshooting
- Query the CAA record for the branded link subdomain:
-
dig <domain.com> CAA(You can also use something like whatsmydns.net and search for CAA records.)
If no CAA record exists on the subdomain, try the root domain:
dig <rootdomain.com> CAA - Look at the Answer section. If records like 0 issue "globalsign.com" appear without an entry for Cloudflare's CA (pki.goog), the policy is blocking issuance of the Twilio SendGrid created certificate.
Resolution
Add a CAA record permitting Google Trust Services (Cloudflare's CA for this setup) to your DNS records. You can review Cloudflare's documentation here.
Verification
- Allow 10-15 minutes for DNS changes to propagate.
- In the SendGrid console, navigate to Settings > Sender Authentication > Link Branding
- Click the Link Branding domain.
-
Click the Verify button. If the SSL certificate was able to be created, you'll see the following: