Auto-Provisioned SSL Branded Links Returning Cloudflare Error 1001 / 409 Conflict

If your branded email links display a Cloudflare Error 1001 (DNS Resolution Error) in a web browser when clicked, your domain's SSL certificate provisioning request has timed out.

Although your DNS settings may show as verified in the SendGrid Console, the underlying SSL certificate request on the edge network has expired and needs to be regenerated.

Environment

  • Product: Twilio SendGrid Email

  • Console: SendGrid App (Settings > Sender Authentication > Link Branding)

  • Feature: Auto-Provisioned SSL Branded Links

Why Is This Happening?

When you create an Auto-Provisioned SSL Branded Link in SendGrid, an automated request is sent to our SSL provider to issue a secure certificate for your custom link subdomain.

  • The 7-Day Verification Window: Cloudflare holds pending SSL certificate requests open for 7 calendar days.

  • The Timeout: If your CNAME records were added to your DNS provider or verified in SendGrid after this 7-day window passed, the pending certificate request was automatically cancelled by the edge network.

  • The Result: Clicking Verify in SendGrid confirms that your CNAME record exists in DNS, but it cannot automatically revive the expired SSL request. Because the edge network lacks an active certificate mapping for your domain, clicking a link in an email leads to Cloudflare Error 1001.

How to Fix It

To trigger a fresh SSL certificate request, you must delete and recreate the link branding configuration in your SendGrid account.

Step 1: Delete the Existing Link Branding Instance

  1. Log into the SendGrid Console.

  2. Navigate to Settings > Sender Authentication > Link Branding.

  3. Locate the affected domain record and click Delete.

Step 2: Re-Create and Verify 

  1. Click Brand Your Links.

  2. Enter the exact same domain and subdomain details you previously used.

  3. Expand Advanced Settings > check Use custom link subdomain and enter the previously generated subdomain

  4. Ensure that all necessary DNS records are in your domain's DNS panel.

  5. Complete the setup and click Verify.

Verification

After completing these steps, allow 10 to 15 minutes for the new SSL certificate to deploy across the global edge network. Once deployed, test a link from a recently sent email or send a new test email to confirm that your branded links redirect smoothly.

 

Have more questions? Submit a request