Challenge failed for domain 🔒 SSL / TLS

Let’s Encrypt / Certbot: Challenge failed for domain example.com — Invalid response from http://example.com/.well-known/acme-challenge/x: 404

Let’s Encrypt couldn’t verify you control the domain — the HTTP-01 challenge file wasn’t served, or DNS points elsewhere.

Seen on: OpenSSL

Meaning

Let’s Encrypt fetches /.well-known/acme-challenge/<token> over port 80. Wrong DNS (old server, IPv6 AAAA to another host), port 80 blocked, redirects to a wrong host, or a CDN/proxy intercepting the path cause failures. DNS-01 challenges fail when TXT records aren’t visible yet.

Common causes

  • DNS A/AAAA records not pointing to this server (stale AAAA common)
  • Port 80 blocked by firewall/security group
  • Web server config not serving the challenge path (redirect/app routing)
  • CDN/proxy (Cloudflare) interfering

⚡ Quick fix

  1. Make DNS point to this server (remove wrong AAAA)
  2. Open port 80 temporarily
  3. Use certbot --nginx/--apache or webroot matching the served root; or DNS-01 with a DNS plugin

Detailed fix by platform

Shell

  1. bash
    dig +short A example.com; dig +short AAAA example.com
    sudo certbot certonly --webroot -w /var/www/html -d example.com -d www.example.com --dry-run

How to diagnose

  1. DNS — A/AAAA records
  2. Reach — curl http://example.com/.well-known/acme-challenge/test
  3. Proxy — CDN in front?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.