An unexpected error occurred: The server will not issue certificates for the identifier :: Error creating new order :: Cannot issue for "": The ACME server refuses to issue a certificate for this domain name, because it is forbidden by policy

I ran this command:sudo certbot certonly --standalone --preferred-challenges http -d

It produced this output:Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator standalone, Installer None
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for
Cleaning up challenges
Problem binding to port 80: Could not bind to IPv4 or IPv6.

Hello @Achref, welcome to the Let's Encrypt community.

Using the online tool Let's Debug with the HTTP-01 challenge of the Challenge Types - Let's Encrypt yields these results

Error has an A (IPv4) record ( but a request to this address over port 80 did not succeed. Your web server must have at least one working IPv4 or IPv6 address.
A timeout was experienced while communicating with Get "": dial tcp i/o timeout

@0ms: Making a request to (using initial IP
@0ms: Dialing
@10000ms: Experienced error: dial tcp i/o timeout 
A test authorization for to the Let's Encrypt staging service has revealed issues that may prevent any certificate for this domain being issued. Fetching Timeout during connect (likely firewall problem) 
Also, it seems your thread title does not correspond with the thread contents, as clearly different errors are presented. How does the policy error relate to the hostname you've mentioned in the thread?


Using this online tool Open Port Check Tool - Test Port Forwarding on Your Router it seem all the Ports are Closed.

And nmap -Pn seems to confirm this.

$ nmap -Pn
Starting Nmap 7.80 ( ) at 2023-04-26 16:34 UTC
Nmap scan report for (
Host is up.
All 1000 scanned ports on ( are filtered

Nmap done: 1 IP address (1 host up) scanned in 202.17 seconds
Most of the questions were left unanswered :frowning:
Is there something bound to port 80?


Apart from the port issue mentioned above, I guess you simply copied the command from user guide and included literally as domain name without any modification, as indicated by the error message in the subject.

The "" domain should not be copied as-is. This should be replaced with your actual domain. in this case, it should be


