SUPPORT.TWILIO.COM END OF LIFE NOTICE: This site, support.twilio.com, is scheduled to go End of Life on February 27, 2024. All Twilio Support content has been migrated to help.twilio.com, where you can continue to find helpful Support articles, API docs, and Twilio blog content, and escalate your issues to our Support team. We encourage you to update your bookmarks and begin using the new site today for all your Twilio Support needs.

Auto-SSL Certificate Provisioning Stuck after Creating Link Branding

Issue

Auto-SSL Custom Link Branding may be stuck on "SSL Certificate Provisioning" despite CNAME DNS records being verified in the SendGrid Console.

Screenshot 2026-09-29 at 12.05.10 PM.png

Product

Twilio SendGrid Email

Cause

When Auto-SSL is enabled, SendGrid uses Cloudflare to manage and issue SSL certificates for your branded link subdomains. Stalled provisioning is typically caused by a CAA Restriction. 

Certification Authority Authorization (CAA) records specify which Certificate Authorities (CAs) are allowed to issue SSL certificates for your domain. If your CAA records restrict issuance to specific CAs (e.g., GlobalSign or DigiCert) without permitting Cloudflare's CAs, certificate provisioning will fail.

Resolution

How to determine if there is a CAA restriction

1. Query the CAA record for the branded link subdomain:

dig <domain.com> CAA

(You can also use a third party service like whatsmydns.net and search for CAA records.)

2. If no CAA record exists on the subdomain, try the root domain:

dig <rootdomain.com> CAA

3. Look at the Answer section. If records like 0 issue "globalsign.com" appear without an entry for Cloudflare's CA (pki.goog), the policy is blocking issuance of the Twilio SendGrid created certificate.

Removing the CAA restriction

Add a CAA record permitting Google Trust Services (Cloudflare's CA for this setup) to your DNS records. You can review Cloudflare's documentation here. 

Verification

1. Allow 10-15 minutes for DNS changes to propagate.

2. In the SendGrid console, navigate to Settings > Sender Authentication > Link Branding 

3. Click the Link Branding domain. 

4. Click the Verify button. If the SSL certificate was able to be created, you'll see the following:

Screenshot 2026-09-29 at 12.02.36 PM.png
Have more questions? Submit a request
Powered by Zendesk