Let’s Encrypt / Certbot: Challenge failed for domain example.com — Invalid response from http://example.com/.well-known/acme-challenge/x: 404
Let’s Encrypt couldn’t verify you control the domain — the HTTP-01 challenge file wasn’t served, or DNS points elsewhere.
Seen on:
OpenSSL
Meaning
Let’s Encrypt fetches /.well-known/acme-challenge/<token> over port 80. Wrong DNS (old server, IPv6 AAAA to another host), port 80 blocked, redirects to a wrong host, or a CDN/proxy intercepting the path cause failures. DNS-01 challenges fail when TXT records aren’t visible yet.
Common causes
- DNS A/AAAA records not pointing to this server (stale AAAA common)
- Port 80 blocked by firewall/security group
- Web server config not serving the challenge path (redirect/app routing)
- CDN/proxy (Cloudflare) interfering
⚡ Quick fix
- Make DNS point to this server (remove wrong AAAA)
- Open port 80 temporarily
- Use certbot --nginx/--apache or webroot matching the served root; or DNS-01 with a DNS plugin
Detailed fix by platform
Shell
- bash
dig +short A example.com; dig +short AAAA example.com sudo certbot certonly --webroot -w /var/www/html -d example.com -d www.example.com --dry-run
How to diagnose
- DNS — A/AAAA records
- Reach — curl http://example.com/.well-known/acme-challenge/test
- Proxy — CDN in front?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 526 Cloudflare Error 526: Invalid SSL Certificate
- doesn't include signing certificate Provisioning profile "x" doesn't include signing certificate "Apple Development: Name (ID)"
- NET::ERR_CERT_COMMON_NAME_INVALID NET::ERR_CERT_COMMON_NAME_INVALID: Your connection is not private (certificate is for a different domain)
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026