Reading · 5 min · Module 6, lesson 3 of 540 min left in this module
Module 6 · Domains and SSLLesson 3 of 5
Goal: Read a custom domain's verification and certificate status, and know what to do at each one.
Key idea
With Automatic selected, ComputeSphere gets an HTTPS certificate for your domain as soon as DNS points at the service, and renews it before it expires. Your only job is the DNS record; the status tells you whether it's right.
The statuses
From your domain to HTTPS
You do
1. Add the domain
In ComputeSphere, on the service's Custom Domain card: app.example.com
2. Create the DNS record
At your DNS provider, exactly as the table lists it:
CNAMEappd-hello-web-3f9c2a71.computesphere.app
ComputeSphere does
Waiting for DNScan't see the record yet
Validatingchecking ownership
Issuing certificateputting it in place
Activeserving HTTPS
Action requirednot live after 72 hours; checks stop
Fix the record, check it with dig @1.1.1.1, then choose Verify now.
ComputeSphere keeps checking on its own; there's no separate verification record. Once Active, the certificate renews automatically.
Each domain in the Custom domain card shows a status. They move in this order:
Status
What it means
What you do
Waiting for DNS
ComputeSphere can't see your record yet
Create it (lesson 5.6.2), then wait
Validating
Ownership is being checked and the certificate requested
Wait
Issuing certificate
Validation passed; the certificate is being put in place
Wait
Active
Serving HTTPS on your domain
Nothing
Action required
It didn't finish, and checks have stopped
Fix the cause, then Verify now
Once DNS is right this usually takes minutes. Active shows green, Action required red, everything between amber. An active domain also shows Valid until and a date; renewal moves it forward on its own.
When it says Action required
ComputeSphere keeps checking a pending domain for up to 72 hours, then parks it at Action required. The cause is almost always DNS:
the record is missing, mistyped, or at a provider that isn't the domain's DNS host;
the record is proxied on Cloudflare (it must be DNS only);
an old record for the same name still points somewhere else.
Fix the record, check it with dig @1.1.1.1, then choose Verify now (the refresh icon next to the domain) to start the checks again straight away. You can use Verify now on any domain that isn't active yet.
Stuck at Validating?
The usual cause is a Cloudflare record still proxied, or a second record (like an old A record) for the same name. Remove the extra record, set the right one to DNS only, and choose Verify now.