Why Let's Encrypt renewals fail

Updated Sep 2026 · 5 min read

The five causes we see most often, and how to catch them early.

1. The validation file is not reachable

curl -i http://harborgoods.com/.well-known/acme-challenge/test

2. DNS moved, the certificate did not

dig +short A harborgoods.com
dig +short AAAA harborgoods.com

3. A CAA record forbids the issuer

dig +short CAA harborgoods.com

4. The renewal ran, but nothing reloaded

openssl s_client -connect harborgoods.com:443 -servername harborgoods.com </dev/null 2>/dev/null \
  | openssl x509 -noout -issuer -dates

5. The renewal job stopped

systemctl list-timers | grep -i certbot
sudo certbot renew --dry-run

And rate limits

Shorter lifetimes ahead

Catch it before visitors do

  1. 1
  2. 2
  3. 3
  4. 4
Building an integration?REST API, webhooks and MCP server are documented separately.Open the docs