# My domain was rejected by Let's Encrypt on Heroku

**URL:** https://community.letsencrypt.org/t/my-domain-was-rejected-by-lets-encrypt-on-heroku/187109
**Category:** Help
**Created:** [November 1, 2022, 7:23pm UTC](https://community.letsencrypt.org/t/my-domain-was-rejected-by-lets-encrypt-on-heroku/187109 "2022-11-01T19:23:28Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![zjones](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/zjones/32/65132_2.png) [@zjones](https://community.letsencrypt.org/u/zjones)
#### Post date: [November 1, 2022, 7:23pm UTC](https://community.letsencrypt.org/t/my-domain-was-rejected-by-lets-encrypt-on-heroku/187109/1 "2022-11-01T19:23:28Z")

</div>

My domain is: [www.letstalkshots.com](http://www.letstalkshots.com)

I ran this command: Attempted to add a certificate automatically while using Heroku

It produced this output: "Domain considered unsafe"

My web server is (include version): gunicorn 20.1.0 on Heroku

The operating system my web server runs on is (include version): Ubuntu 22.04 LTS

My hosting provider, if applicable, is: Heroku

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): Yes, Heroku

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): Not using Certbot, though attempting to get a certification through certbot works. We're trying to find out why the automated process failed and Heroku said to contact Let's Encrypt.

---

<div class="post-metadata">

### Author: ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)
#### Post date: [November 1, 2022, 7:34pm UTC](https://community.letsencrypt.org/t/my-domain-was-rejected-by-lets-encrypt-on-heroku/187109/2 "2022-11-01T19:34:23Z")

</div>

Hello @zjones, welcome to the Let's Encrypt community. 🙂  
Here is a list of issued certificates for [crt.sh | www.letstalkshots.com](https://crt.sh/?q=www.letstalkshots.com), the latest being **2022-10-28**.

Site looks fine from Firefox

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/1/d/1debcf15bf3c565e59b218de648faa286a886d54.png)

And the certificate that is being served seem fine

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/5/8/585f3179999fb52d5babef1d04d6384631e918ba.png)

---

<div class="post-metadata">

### Author: ![zjones](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/zjones/32/65132_2.png) [@zjones](https://community.letsencrypt.org/u/zjones)
#### Post date: [November 1, 2022, 7:47pm UTC](https://community.letsencrypt.org/t/my-domain-was-rejected-by-lets-encrypt-on-heroku/187109/3 "2022-11-01T19:47:45Z")

</div>

Hello! We manually generated a certificate with Let's Encrypt after the automated process on Heroku failed, but we're trying to avoid having to generate a new one manually every time it expires.

Heroku sent the following when we reached out to them:

> Unfortunately, there isn't much that we (Heroku) can do about this directly as we build ACM on top of Let's Encrypt who manages the SSL certification for the domains. If your DNS settings are correct (per our docs) and you're stuck in an ACM status and `heroku certs:auto:refresh` doesn't resolve the issue, you're probably being rate-limited by Let's Encrypt. I would contact [Let'sEncrypt](https://community.letsencrypt.org/) directly to see if they can provide any insight on why the domain's cert generation failed, or perhaps they'll have a workaround for you. As always, we'll be standing by in case we can be of further help as well.

Unclear exactly why it failed, given the manually cert worked fine, but trying to figure out how to resolve it.

---

<div class="post-metadata">

### Author: ![JamesLE](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jamesle/32/49364_2.png) [@JamesLE](https://community.letsencrypt.org/u/JamesLE)
#### Post date: [November 1, 2022, 8:01pm UTC](https://community.letsencrypt.org/t/my-domain-was-rejected-by-lets-encrypt-on-heroku/187109/4 "2022-11-01T20:01:10Z")

</div>

"Domain considered unsafe" isn't an error message that our API ever returns. It would be helpful to find out which error code or message of ours Heroku is encountering.

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [November 2, 2022, 2:25pm UTC](https://community.letsencrypt.org/t/my-domain-was-rejected-by-lets-encrypt-on-heroku/187109/5 "2022-11-02T14:25:04Z")

</div>

I agree with James, we'd need more debug logging to actually find out what's happening here.

It's kinda "easy" of Heroku to just pin the issue with Let's Encrypt while it's not yet clear where the problem even lies.

---

<div class="post-metadata">

### Author: ![zjones](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/zjones/32/65132_2.png) [@zjones](https://community.letsencrypt.org/u/zjones)
#### Post date: [November 3, 2022, 4:58pm UTC](https://community.letsencrypt.org/t/my-domain-was-rejected-by-lets-encrypt-on-heroku/187109/6 "2022-11-03T16:58:54Z")

</div>

Yeah, not loving their response. I'll try the process again and see what happens, and see if they can dig into the details a little more to figure out what's going on.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [December 3, 2022, 4:58pm UTC](https://community.letsencrypt.org/t/my-domain-was-rejected-by-lets-encrypt-on-heroku/187109/7 "2022-12-03T16:58:56Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
