Dual-Gate Packet · Netlify SSL

Custom domain still serving *.netlify.app

$99 USD · one sitting

If DNS verification is SUCCESSFUL, Let's Debug is OK, and HTTP is served by Netlify — but Let's Encrypt still fails (or the browser hostname-fails on apex and www) — the panel check and the ACME check are often not looking at the same topology. This packet diagnoses your records, aliases, primary domain, and exact LE/Netlify error — it does not prescribe universal DNS deletion or wildcard/SAN removal.

The three last-mile sheets
  1. Apex + www / alias topology on the same Netlify site (split DNS, leftover registrar A/ALIAS, wrong primary after adding names on different days).
  2. External-DNS reissue checklist — keep legitimate alias/DNS/primary-domain/certificate checks; fix the actual mismatch before another Provision.
  3. Rate-limit recovery — Let's Encrypt uses token-bucket limits with refill and Retry-After / “retry after …” times. Stop spam-clicking; wait for the actual reset window. There is no “same calendar day always burns another authorization” rule.

If Netlify DNS is in use, Netlify can auto-provision wildcards for that domain — intentional wildcards are not a defect. Strip leftover *.domain SANs only when openssl shows a wildcard you do not need and DNS no longer supports it.

We do not log into your Netlify. Delivery starts only after verified payment and complete intake: Stripe receipt plus the exact domain emailed to gainlyai007@gmail.com. Missing domain (or payment) does not start the deadline. When intake is complete Mon–Fri before 4:00pm America/New_York, we openssl-check live and send the matching sheet(s) the same ET weekday by 11:59pm ET; at/after 4:00pm ET or on Sat/Sun → next ET weekday by 11:59pm ET. Not a guarantee of issuance or Netlify intervention.

Buy the operator packet — $99