This version supports one custom hostname on a site with working HTTPS. Apex/www pairs, additional aliases, wildcard certificates, and automatic deploy subdomains need a coverage review first. We block setup rather than replace a certificate that protects other names.
Before you start
This integration connects your website to verified organization identity—a foundation for your SEO and AEO strategy. See how QWAC fits into search and AI discovery.
- A Netlify site with one exact custom hostname and working HTTPS
- A Netlify token with access to the site and its SSL settings
- An enabled DigiCert Europe or Sectigo account, with business verification and billing arranged
- Access to the DNS provider for domain validation and an active QWAC.com managed service
Netlify serves your organization’s certificate directly. QWAC.com checks the certificate visitors receive, tracks its expiration, and deploys issued replacements. No Cloudflare account is needed.
Account setup time does not include provider identity checks, certificate issuance, or managed-service activation.
Check your custom domain
- Confirm your website is working at its custom hostname over HTTPS.
- Review the primary domain, domain aliases, and HTTPS certificate names. This integration currently needs one hostname; contact us before connecting a site with multiple names.
- Keep the working certificate in place. QWAC.com checks coverage before requesting a replacement.
Your site has one supported hostname and working HTTPS.
Connect Netlify in QWAC.com
- Create a Netlify personal access token with access to your site. Paste it into the secure token field and select Connect Netlify.
- Select the site and hostname, then choose your certificate provider.

The token is encrypted on the backend and is never returned to the browser. Replace it before it expires. This connection uses a token, not OAuth.
The site is linked to your Netlify account.
Choose your issuer and key option
- Connect your DigiCert Europe API account or your enabled Sectigo ACME account.
- Choose We host the key for automatic deployment, or Bring your key and CSR to install certificates yourself.
- Select the purchased QWAC or EV product, then review issuer terms and the request authorization. The issuer charges your own account.
Hosted TLS keys are envelope-encrypted with AWS KMS and decrypted in memory for upload to Netlify. With your own CSR, QWAC.com never receives the private key.
Your certificate request is authorized.
Complete validation
- Add each TXT record shown in the dashboard at your DNS provider, then select Check DNS.
- Complete the issuer’s business checks or representative approval.
- Watch for emails when a new DNS record or another action is needed.
DNS updates are manual, including when Netlify manages your DNS. Fresh validation may be required for reissues.
Your issuer completes its checks and releases the certificate.
Deploy and keep it current
- For hosted keys, we upload the issued certificate, matching key, and issuer chain to Netlify.
- For your own CSR, download the certificate and follow the installation section below.
- Select Sync to check progress. Active means the public website serves the expected certificate.
- Keep issuer and Netlify access current and act on renewal alerts.
Netlify does not renew custom certificates for you. QWAC.com requests and deploys replacements through your enabled issuer account. Do not rely on an automatic fallback after expiry.
Your issued certificate is serving and its renewal is tracked.
Bring your key and CSR
Keep your private key on your own system. QWAC.com needs only the public certificate signing request (CSR). Ask your administrator to generate an RSA-3072 key and a CSR for exactly your website hostname.
Example commands for your administrator
umask 077
openssl req -new -newkey rsa:3072 -nodes -keyout example.com.key -out example.com.csr -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com"Replace example.com with your selected hostname. Keep the .key file private and backed up. Only select the .csr file in QWAC.com.
- Choose your issuer, then Bring your key and CSR.
- Paste or select the public CSR. Connect your issuer account for the selected QWAC or EV product and authorize the request.
- When notified, download the issued certificate from your workspace.
- Open the Netlify site → Domain management → HTTPS → Set custom certificate. Supply the issued certificate, its matching private key, and the issuer’s intermediate CA chain.
- Return to QWAC.com and select Verify Netlify installation. Repeat installation after every reissue.
Your key is uploaded directly to Netlify, which holds it for TLS serving. QWAC.com never receives it. This option does not use Keyless SSL.
Netlify installation instructions ↗Troubleshooting
My site is not listed
Add a custom domain to the correct site and make sure the token can read that site.
Coverage review is required
A site certificate can protect multiple names, including apex and www. The current workflow issues one hostname at a time and will not replace shared coverage. Contact us before changing your domain configuration.
A DNS check is pending
Add the exact TXT value at the authoritative DNS provider. Select Check DNS after it is publicly visible.
Upload needs review
A failed response does not prove the upload failed. We inspect the live certificate before retrying. Contact support if the status remains uncertain.
Official references
Provider screens and requirements change. These links are the source of truth for their platform settings.
Netlify custom certificatesNetlify certificate APINetlify domain troubleshootingKeep this guide handy.
Start with your hosting account, then choose your issuer and how to manage your key.
Register your interest