Case studiesContact

Cloudflare SSL and DNS

Cloudflare SSL certificate mismatch on the apex or www domain

A DNS-to-origin checklist for ERR_SSL_VERSION_OR_CIPHER_MISMATCH, certificate-name errors, apex-to-www failures, Universal SSL coverage, DNS-only records, CAA/DCV issues, SSL mode, origin certificates, and SaaS custom domains.

Do not want to work through every Cloudflare check yourself? Send the current URL, screenshots, and timeline. We can run the buyer-controlled diagnosis and return a fixed-scope DNS, TLS, and redirect evidence pack.

Test every hostname independently

The apex, www, and any multi-level subdomain can resolve differently, use different proxy states, and present different certificates. Capture DNS, TLS certificate names, issuer, validity, HTTP result, and redirect destination for each.

  • Do not assume www and apex share the same path.
  • Record proxied versus DNS-only state.
  • Check the exact browser error code and time.

Separate edge and origin TLS

Visitors normally see Cloudflare's edge certificate on proxied records, while Cloudflare validates the origin separately according to SSL mode. DNS-only records expose the origin or SaaS provider certificate directly.

  • Confirm Universal or custom edge certificate status.
  • Confirm the origin certificate covers the origin hostname.
  • Avoid switching to Flexible as a shortcut for an origin TLS problem.

Validate certificate issuance and redirects

Pending certificates can be caused by DNS/DCV, CAA, DNSSEC, redirects on validation paths, or unsupported hostname depth. After issuance, test redirects without loops and keep the canonical host consistent.

  • Check CAA and DNSSEC.
  • Protect /.well-known validation paths.
  • Verify apex, www, HTTP, HTTPS, and normal browser behavior after the change.
Technical troubleshooting checklist

Work through the evidence in a controlled order.

Each check defines what a healthy result looks like, what to do when it fails, and what evidence to preserve before the next change.

01

DNS and edge certificate checks

Establish what each public hostname resolves to and which certificate visitors receive.

  1. List apex, www, and affected subdomains with A/AAAA/CNAME targets and proxy status.
    Healthy result
    Every hostname has an intentional target and proxied/DNS-only state.
    If it fails
    Remove conflicting records and decide which provider should terminate visitor TLS.
    Save as evidence
    DNS export or redacted record table with timestamp.
  2. Inspect the presented certificate for each hostname.
    Healthy result
    Certificate SAN coverage includes the hostname, validity is current, and the expected provider presents it.
    If it fails
    Identify missing coverage, wrong endpoint, expired custom certificate, or DNS-only exposure.
    Save as evidence
    Issuer, SANs, validity, fingerprint, resolved IP, and error code.
  3. Check Cloudflare Edge Certificates status and Universal SSL coverage.
    Healthy result
    The relevant certificate is Active and covers the apex or first-level subdomain.
    If it fails
    Resolve pending validation, expired custom certificate, or multi-level hostname coverage.
    Save as evidence
    Certificate status, host coverage, and activation time.
  4. Verify CAA, DNSSEC, and domain-control-validation accessibility.
    Healthy result
    DNS resolves consistently, DNSSEC is valid, CAA permits issuance, and validation paths are not redirected or blocked.
    If it fails
    Correct the specific DNS/DCV blocker and wait for revalidation.
    Save as evidence
    CAA/DNSSEC result, validation error, security event, and retest.
02

Origin and redirect checks

Confirm Cloudflare can connect securely to the origin and the canonical host redirect is safe.

  1. Check SSL/TLS encryption mode against the origin's actual certificate and HTTPS support.
    Healthy result
    Full (strict) has a valid origin certificate and the origin serves the expected hostname.
    If it fails
    Install/correct origin TLS or use a deliberate temporary mode only with documented risk and rollback.
    Save as evidence
    Mode, origin certificate subject, origin test, and owner.
  2. Test the origin or SaaS custom-domain status separately from the proxied edge.
    Healthy result
    The provider recognizes the hostname and its required DNS target/verification is complete.
    If it fails
    Finish provider-side custom-domain verification before forcing edge redirects.
    Save as evidence
    Provider domain status, expected CNAME/target, and verification result.
  3. Trace HTTP and HTTPS redirects for apex and www.
    Healthy result
    Every entry path reaches one canonical HTTPS host without a loop or certificate error before redirect.
    If it fails
    Move the redirect to the layer that has valid TLS for the source hostname.
    Save as evidence
    Four-path redirect table with status chain and final URL.
  4. Run post-change TLS, HTTP, browser, and cache validation with rollback ready.
    Healthy result
    Normal and incognito browsers pass, headers and redirects are expected, and no origin exposure was introduced.
    If it fails
    Roll back the last controlled change and compare evidence if any path regresses.
    Save as evidence
    Before/after DNS/TLS matrix, change ID, cache action, and rollback point.
Frequently asked questions

Questions that change the next step.

Does Cloudflare Universal SSL cover every subdomain depth?

Cloudflare documents coverage for the zone apex and one level of subdomain by default. Multi-level hostnames can require advanced or custom certificate coverage.

Why does www work while the bare domain fails?

The two hostnames may have different DNS records, proxy states, certificate coverage, or SaaS mappings. Test them as separate endpoints.

Should I switch Cloudflare to Flexible SSL?

Not as a generic fix. Flexible removes HTTPS between Cloudflare and the origin and can create security and redirect problems. Diagnose edge, origin, and provider TLS first.

What could happen next

A first pass can remain a compact artifact, or expand into a new clearly priced scope with long-term support when the work needs upkeep, rollout help, or follow-up checks.

  • DNS and proxy correction
  • Origin or SaaS domain/TLS configuration
  • Apex-to-www cutover and live verification
CSV hostname matrix

Sample Cloudflare DNS and TLS evidence pack

A realistic apex/www/origin comparison with DNS, proxy, certificate, HTTP, redirect, diagnosis, change, and rollback fields.

  • Hostname-by-hostname TLS evidence
  • Edge versus origin separation
  • Safe change and rollback record
CSV fileCloudflare DNS and TLS evidence matrix

A spreadsheet-ready diagnostic modeled on a paid domain/SSL delivery.

These examples are anonymized. Names, domains, emails, private screenshots, exact products, and private commercial details are removed or generalized.

Contact

Still stuck with Cloudflare?

For a small fixed fee, we can take over the evidence review, controllable corrections, validation, and one clearly bounded support handoff. Platform approval is never guaranteed.

Get Cloudflare help