🔒 Fix Custom Domain SSL Stuck on Pending

Camilo Aponte

Camilo Aponte

Last updated on Sep 30, 2026

🧭 Overview

When you connect a custom domain in Website Studio, Search Atlas automatically provisions an SSL certificate for your site. In most cases this completes within minutes. If the status stays on Pending and your site won't load, the most common cause is an AAAA (IPv6) record on your domain that conflicts with SSL provisioning. This article walks you through diagnosing and fixing that conflict, and clarifies the differences between the setup instructions you may have seen.

⚠️ Why SSL Gets Stuck on Pending

Search Atlas provisions SSL over IPv4. If your domain has an AAAA record (which points to an IPv6 address), your browser or DNS resolver may route requests over IPv6 instead. Because our SSL certificate provisioning service does not respond on that IPv6 path, the verification handshake never completes and the certificate stays in a Pending state indefinitely. The domain appears broken even though every other setting looks correct.

🔍 Step 1 — Check for an AAAA Record

  1. Go to your domain registrar or DNS provider (for example, Cloudflare, GoDaddy, Namecheap, or Route 53).
  2. Open the DNS Management or DNS Records section for your domain.
  3. Look for any record with Type = AAAA. It may be set to your root domain (@) or a subdomain such as www.
  4. If you find one or more AAAA records, continue to Step 2. If you find none, skip to Step 4.

🗑️ Step 2 — Remove the AAAA Record

  1. Select the AAAA record in your DNS provider's dashboard.
  2. Delete it. If your provider asks for confirmation, confirm the deletion.
  3. Repeat for every AAAA record associated with the domain or subdomain you are connecting to Website Studio.
  4. Do not delete A records, CNAME records, or TXT records — only AAAA records.

Note: Removing an AAAA record does not break your domain. It simply stops IPv6 routing, which is not required for Search Atlas to serve your site.

⏳ Step 3 — Wait for DNS Propagation and SSL Renewal

  1. DNS changes can take 5 minutes to 48 hours to propagate worldwide, depending on your provider and your domain's TTL (Time To Live) setting.
  2. After removing the AAAA record, return to Website Studio → Settings → Custom Domain.
  3. If the SSL status still shows Pending, click Retry SSL (or disconnect and reconnect the domain) to trigger a fresh provisioning attempt.
  4. Monitor the status. It should move to Active within a few minutes once DNS has propagated.

✅ Step 4 — Verify Your Required DNS Records

Whether or not you had an AAAA record, confirm that your DNS settings exactly match the following. These are the authoritative values for Website Studio:

  • A record — Point your root domain (@) to the IP address shown in Website Studio → Settings → Custom Domain.
  • CNAME record — Point www to the target hostname shown on the same settings screen (for example, sites.searchatlas.com).
  • No AAAA records on the root domain or www subdomain.

Use a free tool such as dnschecker.org or mxtoolbox.com to confirm your records have propagated before retrying SSL.

📋 A Note on Contradictory Setup Instructions

You may have noticed differences between the setup steps described in our help documentation and the instructions shown by the in-app setup assistant. Here is what each source is intended for:

  • In-app setup assistant (the guided flow inside Website Studio) — These steps are the current, correct instructions. Always follow these when connecting a domain for the first time. They reflect the latest infrastructure configuration.
  • Help Centre articles published before mid-2024 — Some older articles referenced a legacy CNAME-only setup that has since been updated. If an article tells you to point @ to a CNAME target rather than an A record, that article is outdated. Follow the in-app instructions instead.

We are actively auditing and updating older documentation to remove this inconsistency. We apologise for any confusion this has caused.

🛠️ Quick Troubleshooting Checklist

  • AAAA record removed from DNS? Yes / Not applicable
  • A record for @ pointing to the correct IP? Yes
  • CNAME for www pointing to the correct target? Yes
  • DNS propagation confirmed via dnschecker.org? Yes
  • SSL Retry triggered in Website Studio after DNS update? Yes
  • Waited at least 15 minutes after retrying? Yes

If all items above are checked and SSL is still showing Pending after 2 hours, escalate using the contact method below.

💬 Still Need Help?

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be connected with a member of our team.