Diagnosing Scalingo Automatic HTTPS Certificate Provisioning Failures
Troubleshoot Scalingo HTTPS certificate failures: verify domain entry, DNS, propagation, rate limits, app restart, and platform logs, then apply fixes or escalate.
19 Jul 2025, 23:10 UTC

Recognizable condition
When you try to reach your Scalingo application via https:// the browser shows a certificate warning, the connection times out, or the request falls back to plain HTTP. This indicates that Scalingo has not successfully obtained a TLS certificate for the hostname.
Possible causes
| Possible cause | What you might see |
|---|---|
| Domain not added in the Scalingo dashboard | The Domains tab does not list the hostname. |
| DNS records point elsewhere | dig returns an address that is not Scalingo’s routers. |
| DNS propagation delay | Records look correct but recent changes have not yet propagated. |
| Let's Encrypt rate limit exceeded | Recent certificate requests for the same domain have triggered a temporary block. |
| App not restarted after adding the domain | The domain appears in the dashboard but no new deployment was triggered. |
| Underlying platform issue | The dashboard shows an error like “Failed to obtain certificate” with no obvious reason. |
Ordered checks
- Log in to the Scalingo dashboard, open your app, and verify that the hostname appears under the Domains tab. If it is missing, note that you need to add it.
- From a terminal where you have access to
digornslookup, run:
Replacedig +shortwith your actual hostname (e.g.,www.example.com). The answer should be either a CNAME pointing to<app>.scalingo.ioor an A record matching one of Scalingo’s router IPs (consult the Scalingo documentation for the current list). If the answer points elsewhere, the DNS configuration is wrong. - If you just changed the DNS record, check the TTL value (e.g., with
dig +nocmd any +multiline +answer) and wait until the TTL has elapsed before re‑checking. A common practice is to lower the TTL to 300 seconds before making changes to reduce waiting time. - Trigger a new deployment (e.g., push an empty commit) and watch the logs for lines such as
Obtaining certificate from Let's Encryptor any error messages. You can view logs with the Scalingo CLI:
Look for timestamps around the moment you pushed the commit.scalingo --app logs - Visit and check whether your domain (or the registered domain) has exceeded the “Certificates per Registered Domain” limit (50 per week). If you see a lock‑out note, you have hit a rate limit.
- Ensure the application was restarted after the domain was added. Run:
to see the release identifier, then compare with the timestamp of the domain addition. If the release is older, restart:scalingo --app psscalingo --app restart
Fixes tied to findings
- Domain missing: In the dashboard, add the hostname under Domains → Add domain. Then push a git commit (even an empty one) to trigger a redeploy, which prompts Scalingo to request a certificate.
- Wrong DNS: Update the DNS record at your provider:
- For a CNAME, set
www(or your subdomain) to<app>.scalingo.io. - For an A record, point to the IPs listed in Scalingo’s platform documentation.
- For a CNAME, set
- Propagation delay: If the records are correct but still not resolving, simply wait. You can verify propagation with
dig +tracefrom multiple resolvers or use an online DNS checker. - Rate limit hit: Wait for the lock‑out period (usually 1 hour for the “Failed to validate” limit, longer for the per‑domain limit). In the meantime, you can use a temporary subdomain (e.g.,
dev.example.com) that has not been used recently. - App not restarted: Run the restart command shown above, or redeploy with
git push scalingo main. A new release will cause Scalingo to retry certificate provisioning. - Platform issue: Collect the relevant log snippet (e.g., lines containing “Failed to obtain certificate”) and open a support ticket via the Scalingo dashboard, providing app name, domain, timestamps, and the log excerpt.
Escalation criteria
If after completing all of the above checks the certificate is still absent after 24 hours, or you repeatedly encounter Let's Encrypt rate limits despite waiting, or the dashboard displays a persistent error like Failed to obtain certificate with no clear cause, escalate to Scalingo support. Include:
- Application name (
) - Exact domain (
) - Timestamps of when you added the domain and when you last pushed a redeploy
- Relevant log lines (copy‑paste, no more than 200 characters)
- Output of the DNS check (
dig +short)
Verification and practical way to check the result
After you believe the issue is resolved, confirm TLS is active:
- Run:
Look forcurl -I https://HTTP/2 200orHTTP/1.1 200 OKand the presence of astrict-transport-securityheader. Absence of these indicates TLS is not yet serving. - Use an external SSL tester such as and enter your domain. The report should show a valid certificate chain, the correct hostname, and a grade of at least “A”.
- In the Scalingo dashboard, the Domains list should display a green lock icon next to the hostname and show the certificate’s expiry date.
If any of these checks still fail, repeat the ordered checks from step 1.
Limitations
- The guide assumes you have access to the Scalingo CLI and the ability to modify DNS records at your provider.
- Let's Encrypt rate limits are subject to change; the numbers quoted (50 certificates per registered domain per week) are accurate as of the time of writing but may differ.
- DNS propagation times depend on the TTL set by your DNS provider; lowering the TTL beforehand reduces waiting time but may increase query load.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.