"Invalid Domain" Renewing or Creating New? Synology

I've searched the web, read many posts/guides, and tested a ton.. so hoping someone here has a real solution, not a guess... I've read all the guesses I think! :wink:

Tried renewing the not-yet expired cert. The deleted that cert and tried creating new -- same problem both ways.

"Invalid domain. Make sure the domain name can resolve to public IP."


  • Synology 'Web Server' service on and off
  • my DDNS IP is resolved properly using multiple test sites
  • ports 80/443 test good withcanyouseeme.org and letsdebug.net
  • TCP & UDP 80/443 all forwarded from firewall to Synology (no other open ports)


  • Synology on latest DSM with all updates
  • Reverse Proxy running on Synology
  • Synology Firewall is Off
  • PiHole running on Synology, in Docker

I don't think you've provided enough information for anyone to even take a normal guess.
At this point, it would be a wild guess on my part.

If you could please provide more details.
Starting with: Answering the questions that are provided to all "Help" topics.

And in addition... Since you showed the error message "`Invalid domain`", the FQDN shown in that error message. Since you mentioned "proxy", the proxy settings [as they relate to the FQDN involved]. Since you mentioned ports being forwarded, those firewall NAT settings as well.

The Redirect is incorrect

$ curl -Ii http://canyouseeme.org/.well-known/acme-challenge/sometestfile
HTTP/1.1 302 Found
Date: Sun, 07 May 2023 18:12:31 GMT
Server: Apache/2.4.7 (Ubuntu)
Location: https://canyouseeme.org.well-known/acme-challenge/sometestfile
Content-Type: text/html; charset=iso-8859-1

This URL http://canyouseeme.org/.well-known/acme-challenge/sometestfile redirects to https://canyouseeme.org.well-known/acme-challenge/sometestfile

Please note the canyouseeme.org.well-known appears to be missing a forward slash.
I believe the redirected URL should look like https://canyouseeme.org/well-known/acme-challenge/sometestfile

$ curl -Ii https://canyouseeme.org/well-known/acme-challenge/sometestfile
HTTP/1.1 404 Not Found
Date: Sun, 07 May 2023 18:15:05 GMT
Server: Apache/2.4.7 (Ubuntu)
Content-Type: text/html; charset=iso-8859-1

Also using the online tool Let's Debug yields these results https://letsdebug.net/canyouseeme.org/1471495

Sending an ACME HTTP validation request to canyouseeme.org results in an unacceptable redirect. This is most likely a misconfiguration of your web server or your web application.
It appears that a redirect was generated by your web server that is missing a trailing slash after your domain name: https://canyouseeme.org.well-known/acme-challenge/letsdebug-test. Check your web server configuration and .htaccess for Redirect/RedirectMatch/RewriteRule.

@0ms: Making a request to http://canyouseeme.org/.well-known/acme-challenge/letsdebug-test (using initial IP
@0ms: Dialing
@14ms: Server response: HTTP 302 Found
@14ms: Received redirect to https://canyouseeme.org.well-known/acme-challenge/letsdebug-test 
A test authorization for canyouseeme.org to the Let's Encrypt staging service has revealed issues that may prevent any certificate for this domain being issued. Fetching https://canyouseeme.org.well-known/acme-challenge/OLLFrrd9-QZAq1u2dNwJMGYG6kzwm0LXVX-DnFeqv64: Invalid host in redirect target "canyouseeme.org.well-known". Check webserver config for missing '/' in redirect target. 

Its working now... as a whim, I removed the "www" from the list provided to 'Subject Alternative Name' and it worked! I assumed I needed the A NAME, but looks like I only needed the CNAMEs?