Guides · Fix a certificate error
Let's Encrypt renewal failed: common causes and how to fix them
Last reviewed by a person on October 4, 2026
Let's Encrypt certificates last 90 days and are meant to renew by themselves, usually through certbot or a similar ACME client.
When renewal quietly stops working you find out when the certificate expires. And since June 4, 2025, Let's Encrypt no longer
sends expiry reminder emails, so no email warns you any more. This guide helps you find out why a renewal failed, or why a
renewed certificate is not showing up.
Step 1: ask the client what is wrong
sudo certbot renew --dry-run sudo tail -n 80 /var/log/letsencrypt/letsencrypt.log
The dry run goes through the real process against Let's Encrypt's test servers without issuing anything. It names the failing domain and the reason. If you use another client (acme.sh, Caddy, Traefik, a hosting panel), use its own test or log.
Step 2: the usual causes
- Port 80 is not reachable (HTTP-01 challenge). Let's Encrypt fetches a file from
http://yourdomain/.well-known/acme-challenge/…. A firewall, a changed security group, a redirect rule that sends everything to HTTPS before the challenge is answered, or a proxy in front can stop it. Test it from outside, not from the server itself. - The DNS no longer points here. The challenge goes to wherever the domain points now. If you moved the site, changed to a CDN, or the name now resolves to another server, validation reaches the wrong place.
- DNS-01 problems (wildcards, or servers without port 80). The client must create a TXT record. An expired API token, a changed DNS provider, or a record that has not propagated all fail it.
- A CAA record forbids it. If your DNS has CAA records that do not list
letsencrypt.org, issuance is refused with "CAA record … prevents issuance". See CAA records explained. - Rate limits. Repeated failures trigger them: for example 5 failed validations per account, per hostname, per hour, and 5 identical certificates per week. Fix the cause first, then wait; retrying in a loop makes it worse. Use
--dry-runor the staging environment while you debug. - The renewal job is not running. Check with
systemctl list-timers | grep -i certbot(or your crontab). A server rebuilt, certbot installed twice (apt and snap) or a disabled timer are common. - Webroot or config changed. The client remembers where it put challenge files. If you changed the web server's document root or removed a vhost, the saved path is wrong.
- An outdated client. Very old certbot versions stop working when the ACME protocol or its certificates change. Update it.
"It renewed, but the site still shows the old certificate"
Renewal writes the new certificate to disk. The web server keeps serving the old one from memory until it reloads. Make the reload part of the renewal:
sudo certbot renew --deploy-hook "systemctl reload nginx" # or set it once in /etc/letsencrypt/renewal-hooks/deploy/
Also check that the server points at the live files (/etc/letsencrypt/live/yourdomain/fullchain.pem) and not a copy, and that
every server or load balancer behind the name got the new certificate. See
SSL certificate expired for how to confirm which certificate is really served.
Do not rely on emails from Let's Encrypt
Renewal failures are quiet by nature, and the reminder emails that used to be the safety net ended in June 2025. Let's Encrypt itself points to independent monitoring for anyone who wants warnings. You want a check that does not live on the server that might be failing.
CertAvert checks your certificate from outside every day and emails you at 30, 14 and 7 days (Starter and Pro; Free gets 30 days and when it expires), and on paid plans also when it finds a problem such as a broken chain. Because certbot normally renews when about 30 days are left, a Let's Encrypt certificate that reaches the 14-day or 7-day warning is a clear sign that renewal is not working. With Let's Encrypt's 6-day certificates the warning comes at 2 days left instead, after the renewal should already have happened. The SSL/TLS checker shows the current expiry date for any domain.
Don't wait for the browser warning
Check any site's certificate in a few seconds with the SSL/TLS checker, or sign up free and CertAvert emails you before certificates expire.