Cloudflare SSL certificate mismatch on the apex or www domain
A DNS-to-origin checklist for ERR_SSL_VERSION_OR_CIPHER_MISMATCH, certificate-name errors, apex-to-www failures, Universal SSL coverage, DNS-only records, CAA/DCV issues, SSL mode, origin certificates, and SaaS custom domains.
Do not want to work through every Cloudflare check yourself? Send the current URL, screenshots, and timeline. We can run the buyer-controlled diagnosis and return a fixed-scope DNS, TLS, and redirect evidence pack.
The apex, www, and any multi-level subdomain can resolve differently, use different proxy states, and present different certificates. Capture DNS, TLS certificate names, issuer, validity, HTTP result, and redirect destination for each.
Do not assume www and apex share the same path.
Record proxied versus DNS-only state.
Check the exact browser error code and time.
Separate edge and origin TLS
Visitors normally see Cloudflare's edge certificate on proxied records, while Cloudflare validates the origin separately according to SSL mode. DNS-only records expose the origin or SaaS provider certificate directly.
Confirm Universal or custom edge certificate status.
Confirm the origin certificate covers the origin hostname.
Avoid switching to Flexible as a shortcut for an origin TLS problem.
Validate certificate issuance and redirects
Pending certificates can be caused by DNS/DCV, CAA, DNSSEC, redirects on validation paths, or unsupported hostname depth. After issuance, test redirects without loops and keep the canonical host consistent.
Check CAA and DNSSEC.
Protect /.well-known validation paths.
Verify apex, www, HTTP, HTTPS, and normal browser behavior after the change.
Technical troubleshooting checklist
Work through the evidence in a controlled order.
Each check defines what a healthy result looks like, what to do when it fails, and what evidence to preserve before the next change.
01
DNS and edge certificate checks
Establish what each public hostname resolves to and which certificate visitors receive.
List apex, www, and affected subdomains with A/AAAA/CNAME targets and proxy status.
Healthy result
Every hostname has an intentional target and proxied/DNS-only state.
If it fails
Remove conflicting records and decide which provider should terminate visitor TLS.
Save as evidence
DNS export or redacted record table with timestamp.
Inspect the presented certificate for each hostname.
Healthy result
Certificate SAN coverage includes the hostname, validity is current, and the expected provider presents it.
Issuer, SANs, validity, fingerprint, resolved IP, and error code.
Check Cloudflare Edge Certificates status and Universal SSL coverage.
Healthy result
The relevant certificate is Active and covers the apex or first-level subdomain.
If it fails
Resolve pending validation, expired custom certificate, or multi-level hostname coverage.
Save as evidence
Certificate status, host coverage, and activation time.
Verify CAA, DNSSEC, and domain-control-validation accessibility.
Healthy result
DNS resolves consistently, DNSSEC is valid, CAA permits issuance, and validation paths are not redirected or blocked.
If it fails
Correct the specific DNS/DCV blocker and wait for revalidation.
Save as evidence
CAA/DNSSEC result, validation error, security event, and retest.
02
Origin and redirect checks
Confirm Cloudflare can connect securely to the origin and the canonical host redirect is safe.
Check SSL/TLS encryption mode against the origin's actual certificate and HTTPS support.
Healthy result
Full (strict) has a valid origin certificate and the origin serves the expected hostname.
If it fails
Install/correct origin TLS or use a deliberate temporary mode only with documented risk and rollback.
Save as evidence
Mode, origin certificate subject, origin test, and owner.
Test the origin or SaaS custom-domain status separately from the proxied edge.
Healthy result
The provider recognizes the hostname and its required DNS target/verification is complete.
If it fails
Finish provider-side custom-domain verification before forcing edge redirects.
Save as evidence
Provider domain status, expected CNAME/target, and verification result.
Trace HTTP and HTTPS redirects for apex and www.
Healthy result
Every entry path reaches one canonical HTTPS host without a loop or certificate error before redirect.
If it fails
Move the redirect to the layer that has valid TLS for the source hostname.
Save as evidence
Four-path redirect table with status chain and final URL.
Run post-change TLS, HTTP, browser, and cache validation with rollback ready.
Healthy result
Normal and incognito browsers pass, headers and redirects are expected, and no origin exposure was introduced.
If it fails
Roll back the last controlled change and compare evidence if any path regresses.
Save as evidence
Before/after DNS/TLS matrix, change ID, cache action, and rollback point.
Frequently asked questions
Questions that change the next step.
Does Cloudflare Universal SSL cover every subdomain depth?
Cloudflare documents coverage for the zone apex and one level of subdomain by default. Multi-level hostnames can require advanced or custom certificate coverage.
Why does www work while the bare domain fails?
The two hostnames may have different DNS records, proxy states, certificate coverage, or SaaS mappings. Test them as separate endpoints.
Should I switch Cloudflare to Flexible SSL?
Not as a generic fix. Flexible removes HTTPS between Cloudflare and the origin and can create security and redirect problems. Diagnose edge, origin, and provider TLS first.
Official documentation reviewed
Primary sources for the checklist.
Platform interfaces and policies change. These official pages are the baseline; account-specific evidence still determines the correct action.
A first pass can remain a compact artifact, or expand into a new clearly priced scope with long-term support when the work needs upkeep, rollout help, or follow-up checks.
DNS and proxy correction
Origin or SaaS domain/TLS configuration
Apex-to-www cutover and live verification
CSV hostname matrix
Sample Cloudflare DNS and TLS evidence pack
A realistic apex/www/origin comparison with DNS, proxy, certificate, HTTP, redirect, diagnosis, change, and rollback fields.
Hostname-by-hostname TLS evidence
Edge versus origin separation
Safe change and rollback record
CSV fileCloudflare DNS and TLS evidence matrix
A spreadsheet-ready diagnostic modeled on a paid domain/SSL delivery.
These examples are anonymized. Names, domains, emails, private screenshots, exact products, and private commercial details are removed or generalized.
Contact
Still stuck with Cloudflare?
For a small fixed fee, we can take over the evidence review, controllable corrections, validation, and one clearly bounded support handoff. Platform approval is never guaranteed.