Skip to content
UK web hosting, domain names, email, website security and online services.

Troubleshoot SSL for a reseller customer domain Print

  • domain, troubleshooting, reseller, ssl, dns
  • 0

Certificate issuance must validate the customer hostname against the correct SiteWorx account over every public address.

Applies to: Reseller DNS, SSL and email

Each customer account needs correct DNS, SSL and email configuration. The reseller controls customer-facing setup, but Tudor Internet controls the underlying shared platform and network.

Before you start

  • Sign in with the reseller account rather than a customer SiteWorx login.
  • Identify the affected SiteWorx account, package and domain.
  • Record the current package, DNS and account settings before making a production change.
  • Allow for DNS caching and avoid making unrelated DNS changes during the same maintenance window.

Work through these checks

  1. Confirm the domain is assigned to the intended SiteWorx customer and its public A and AAAA records point to the hosting platform.
  2. Check that no CDN, proxy or redirect blocks the validation path.
  3. Run the SiteWorx Let’s Encrypt or AutoSSL action for the exact required hostnames.
  4. Review the failure details rather than repeating issuance until rate limits are reached.
  5. Remove stale AAAA or conflicting DNS only after confirming it is not used by another service.
  6. After issuance, test the served certificate on www and non-www names and enable HTTPS redirect.
  7. Escalate platform-level issuance failures with the customer account, hostname, timestamp and validation result.

Common problems

SymptomLikely causeWhat to do
Some networks show the new result while others show the old one.Recursive DNS caches have not expired or authoritative nameservers do not return consistent data.Check the authoritative answer first, compare all listed nameservers and wait for the previous TTL before making another change.
The domain returns NXDOMAIN or SERVFAIL.The zone is missing, delegation is wrong, DNSSEC is broken or an authoritative server is not responding.Verify delegation at the registry, confirm the zone exists on every authoritative server and remove stale DS records only through a controlled DNSSEC rollback.
Certificate issuance fails.The domain does not resolve to the hosting server, an incorrect AAAA record exists, or validation requests are redirected or blocked.Confirm public A and AAAA answers, allow HTTP validation to reach the account and retry only after DNS is correct to avoid rate limits.
The browser still shows an old or invalid certificate.A proxy, CDN, alternate hostname or cached connection is presenting a different certificate.Check the certificate actually served for each hostname and test both IPv4 and IPv6 paths before reinstalling anything.

Important notes

  • Make production changes in a planned window, keep the old configuration recorded and avoid changing several dependent services at the same time.

When to contact Tudor Internet

Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:

  • The reseller service and affected SiteWorx account
  • The package name and current resource use
  • The exact action attempted and error returned
  • Whether the issue affects one or multiple customer accounts
Do not send passwords, private keys, full payment-card details, one-time authentication codes or unredacted identity documents in an ordinary support reply.

Related articles

Last reviewed: 2026-07-18.


Was this answer helpful?

« Back