Why Let's Encrypt renewals fail
Updated Sep 2026 · 5 min readThe five causes we see most often, and how to catch them early.
1. The validation file is not reachable
curl -i http://harborgoods.com/.well-known/acme-challenge/test2. DNS moved, the certificate did not
dig +short A harborgoods.com
dig +short AAAA harborgoods.com3. A CAA record forbids the issuer
dig +short CAA harborgoods.com4. The renewal ran, but nothing reloaded
openssl s_client -connect harborgoods.com:443 -servername harborgoods.com </dev/null 2>/dev/null \
| openssl x509 -noout -issuer -dates5. The renewal job stopped
systemctl list-timers | grep -i certbot
sudo certbot renew --dry-runAnd rate limits
Shorter lifetimes ahead
Catch it before visitors do
- 1
- 2
- 3
- 4