ACME Preflight Checker - Test HTTP-01 & DNS-01 Before Issuing

ACME Challenge Preflight Checker

Simulate the checks Let's Encrypt runs before issuance and fix problems before you burn a rate-limit slot.

Validates via http://domain/.well-known/acme-challenge/ — needs port 80 reachable.

About ACME Challenge Preflight Checker

The CSR.plus ACME Challenge Preflight Checker runs the exact checks Let's Encrypt performs before it issues a certificate. Instead of waiting for an authorization failure and debugging it blind, you verify HTTP-01 or DNS-01 readiness in one click: DNS resolution, TCP 443 connectivity, .well-known/acme-challenge reachability and the _acme-challenge TXT record.

Every failed check comes with a concrete fix suggestion, so a failed preflight tells you exactly what to change in your DNS zone, web server or firewall before you waste one of your limited issuance attempts.

Why use

  • Simulates both HTTP-01 and DNS-01 validation from outside your network
  • Detects DNS not resolving, blocked challenge paths, WAF interference and missing TXT records
  • Optional expected TXT value check for DNS-01
  • 13 languages with per-problem repair instructions

How to use

  1. Enter the domain you plan to request a certificate for.
  2. Choose the validation method your ACME client will use (HTTP-01 or DNS-01).
  3. For DNS-01, optionally paste the TXT value Let's Encrypt gave you.
  4. Run the preflight and fix every failed check using the suggestions.

Frequently asked questions

▸What does an ACME preflight check?

It checks DNS resolution (A/AAAA records), TCP connectivity on port 443, HTTP-01 reachability of the .well-known/acme-challenge path, and DNS-01 TXT records at _acme-challenge.yourdomain — the same conditions Let's Encrypt validates before issuance.

▸Why did my Let's Encrypt challenge fail?

The most common causes are DNS not yet propagated, a WAF or CDN blocking the challenge path, a firewall blocking port 80/443, or a missing or mistyped _acme-challenge TXT record. The preflight reports exactly which of these is breaking your domain.

▸Does the preflight consume a Let's Encrypt rate limit?

No. It performs its own DNS lookups and HTTP requests and never contacts Let's Encrypt, so it costs nothing against your issuance quota.

▸HTTP-01 vs DNS-01: which should I use?

HTTP-01 needs port 80 reachable and a web server; DNS-01 needs a TXT record and works with wildcard certificates. Use HTTP-01 when you control the server, DNS-01 when you use a CDN or need wildcards.

Namecheap

Need a new SSL certificate?

DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.

Get SSL on Namecheap

Affiliate link — we may earn a commission at no extra cost to you.

More free tools

Certificate Viewer

Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.

Certificate / Key Matcher

Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.

PEM Viewer

Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.

SSL Format Converter

Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.

SSL Checker (A-F Grade)

Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.

SSL Bulk Checker

Check multiple SSL certificates at once

Let's Encrypt Checker

Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.

DNS Propagation Checker

Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.

LE Chain Compatibility

See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.

ACME Command Generator

Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.

Certificate Inspector

Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.

SSL Expiry Checker

Quickly check a domain's SSL certificate expiry date and remaining days.

Certificate Transparency Lookup

List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.

CAA Record Checker

Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.

Certificate Revocation Checker

Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.

SSL Handshake Tracer

Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.