_acme-challenge

We noticed the DNS records for www.example.com are still pointing to a previous host, though your site was recently migrated to Kinsta. We want to remind you that your website traffic won’t be directed to Kinsta until you update your DNS records.

  1. The only thing wrong was a missing _acme-challenge CNAME. The traffic to the site was fine. A somewhat over-dramatic email for a missing CNAME, don’t you think?
  2. Why wasn’t the _acme-challenge CNAME added automatically? Kinsta do the DNS - it could have been added when I imported the old DNS records, or when I created the new A record, or when the system noticed it was missing.
  3. And if you don’t want to do it automatically, where’s the button that says “Add _acme-challenge record”? You gave me the record to copy/paste from one screen to the other - why do I have to faff about adding it by hand?
  4. Why was there a load of boilerplate around how long DNS takes to update etc? It’s almost like that part of the service doesn’t know Kinsta are doing the DNS…
  5. … just like the Domains page where it’s now “Domain verification pending”.

These are sharper edges than I was expecting from Kinsta. Maybe I’m holding it wrong?

Hello there :waving_hand: Welcome to the community @invisnet :tada:

Given that this is in regards to the live domain, I would advise opening a chat with our support team to address your concerns.

The CNAME record for _acme-challenge is added for the purposes of generating SSL, but this would depend on whether you choose Quick setup (non-wildcard, only pointing with A record), or the setup that requires verification.

Also Kinsta DNS won’t automatically generate your records, you can scan automatically if your domain exist elsewhere to get the records from another provider.

But again, I advise reaching out in chat for details :+1:

Hi @VladimirM

This isn’t a support request - everything is working, I assume the domain verification will happen at some point.

This is feedback on the process of getting there.

Kinsta are doing the DNS. Kinsta are hosting the website. There are no other significant moving parts.

I had to copy/paste a record from one Kinsta screen to another Kinsta screen, a record which is solely for Kinsta to generate an SSL cert for a site Kinsta hosts.

There’s a common theme there…

Obviously DNS can be hideously complex, but in the simple case - such as this - things should be simple.

Your system detected the record was missing. In the simple case, it should just add the record.

Hi @invisnet!

Thank you for your reply! I certainly understand that having to separately add the _acme-challange to your domain’s Kinsta DNS zone adds additional friction and is something that could be automated.

I am escalating this matter internally with our development team to take a look and see what occurred here. As I understand your domain’s authoritative nameservers are configured to use Kinsta DNS. In this case that should have been detected.

We appreciate you sharing this feedback with us and we will get to the bottom of what happened here to ensure a smoother experience for you going forward.

If you do have any additional questions please don’t hesitate to reach out. We are always happy to help.