Problem
You added your domain in the Vercel dashboard, pasted some DNS records into your registrar, and now you’re staring at a red Invalid Configuration or a certificate that’s been “pending” for an hour. The Vercel preview URL (your-project.vercel.app) works fine. Your actual domain doesn’t — it either shows the old site, a DNS error, or a certificate warning. Nothing in the dashboard tells you which of the half-dozen things you touched is the one that’s wrong.
Almost every stuck Vercel domain is one of three problems, and they fail at three different layers: the records point the wrong way, the change hasn’t reached resolvers yet, or the certificate can’t issue. Check them in that order and you’ll find the one that’s biting you.
The apex and www need different records — and you can’t swap them
This is where most setups go wrong, because the two names your users type look interchangeable and aren’t.
- The apex — the bare
example.com. This takes an A record pointing at Vercel’s IP. The value is76.76.21.21for most projects, but don’t take my word for it: Vercel prints the exact value you need on the domain’s page inside your project. Use that one. www(and any other subdomain). This takes a CNAME pointing atcname.vercel-dns.com.
You cannot flip these and give the apex a CNAME. The DNS spec forbids a CNAME from coexisting with other records at a name, and the zone apex is required to carry SOA and NS records — so a CNAME there is illegal. That constraint is the whole reason Vercel’s instructions look asymmetric: an A record for the root it can give you a fixed IP for, a CNAME for www so it can steer that traffic. If your DNS provider offers “ALIAS,” “ANAME,” or “CNAME flattening” for the apex, that’s a vendor workaround for the same limitation and also fine — but a plain CNAME on the root will either be rejected or silently break the rest of your zone.
The clean alternative to editing records at all is to change your domain’s nameservers to Vercel’s (Vercel shows these too — ns1.vercel-dns.com / ns2.vercel-dns.com), which hands the whole zone to Vercel and lets it manage the apex and www for you. Pick one approach. Don’t do half of each.
“Invalid Configuration” is a propagation answer, not a verdict
Once the records are right, Vercel still has to see them, and so does the rest of the internet. DNS changes don’t apply the instant you save — resolvers hold the previous answer until its TTL expires, which is why the domain can keep showing your old host for minutes to hours after you’ve fixed everything.
Two traps live here:
- You edited the wrong place. If the domain’s nameservers were long ago pointed at an external DNS provider, the record you just changed at your registrar is a dead letter — nothing reads it. The records only count at whatever nameservers the delegation actually points to. (If you’re not sure where that is, that’s its own problem: see Find Your Domain’s Nameservers and DNS Provider.)
- You’re reading the panel, not reality. The registrar’s panel showing the right value doesn’t mean resolvers return it yet. Check what’s actually resolving worldwide before you conclude the config is broken — a correct record mid-propagation looks identical to a missing one in the Vercel dashboard.
Vercel re-checks on its own and flips to Valid Configuration the moment the correct answer propagates. If the records are genuinely right, this is a waiting game, not a fixing one.
SSL issues itself — unless something blocks the challenge
Vercel requests a free certificate (from Let’s Encrypt) for your domain automatically; you don’t generate or upload anything. But it can only issue once your domain resolves to Vercel and the issuance challenge can complete. The two things that keep a certificate “pending” after DNS is otherwise correct:
- A CAA record that doesn’t allow the CA. If your domain has a CAA record, it’s an allowlist of which certificate authorities may issue for you. If it doesn’t name Let’s Encrypt, the CA is obligated to refuse — and your certificate never issues, silently. Either remove the CAA record or add an entry for
letsencrypt.org. - A proxy sitting in front. A Cloudflare (or similar) record left on proxied / orange-cloud intercepts the connection, so the challenge hits the proxy instead of Vercel. Set the record to DNS-only during setup. You can reconsider a proxy later, but not while Vercel is trying to validate the domain.
With DNS pointing at Vercel, no hostile CAA, and no proxy in the way, the certificate lands within a few minutes.
Diagnose with DechoNet
- DNS Lookup reads the A record on your apex and the CNAME on
wwwstraight off the authoritative nameservers, so you can confirm they actually point at Vercel’s IP andcname.vercel-dns.com— not just that you typed them into a panel. It also shows any CAA record that might be blocking the certificate. - Propagation Check shows whether resolvers around the world are returning the new records yet, which is the difference between “my config is broken” and “I need to wait for the old TTL to expire.”
- SSL Check confirms, once the domain resolves to Vercel, that a valid certificate has actually been issued and is being served for both the apex and
www— the final step that turns off the browser warning.
Verification Checklist
- Apex (
example.com) has an A record with the exact value Vercel shows on the domain’s page (usually76.76.21.21) — not a CNAME. -
wwwhas a CNAME tocname.vercel-dns.com(or you’ve delegated the whole domain to Vercel’s nameservers — one approach, not both). - You’re editing DNS at the provider the domain’s nameservers actually point to, not a registrar panel that’s no longer authoritative.
- A propagation check shows resolvers returning the new records — if not, the config may be right and still mid-propagation.
- No CAA record blocks the CA (remove it or allow
letsencrypt.org), and no record is left proxied in front of Vercel. - After DNS is correct, an SSL check shows a valid certificate on both the apex and
www.
When to Escalate
- If DNS resolves correctly to Vercel everywhere and the dashboard still says Invalid Configuration after the old TTL has fully expired, it’s worth re-adding the domain in Vercel to force a fresh check — a stale verification state, not a DNS problem.
- If the certificate stays pending with correct DNS, no CAA, and no proxy, the blocker is on the issuance side — check Vercel’s domain page for a specific challenge error rather than re-editing records that are already right.
- If you’re pointing an apex at Vercel but your DNS provider has no A/ALIAS option at the root at all, you can’t host the bare domain there — either move DNS to a provider that supports apex records (or Vercel’s own nameservers), or serve the site from
wwwand redirect the apex to it.
Check your own domain now
Free, no sign-up. Runs the exact check this guide describes and shows what to fix.