Custom scan domain and SSL before ink
SmartQRCode editorial · Updated October 2026
Custom scan domain and SSL must finish before the host is written into pixels. pending_dns, verifying, and txt_challenge are not print-ready. Browsers warn. Cartons cannot be patched with a later certificate. A Canva PNG still wins when you will never edit or count.
Why custom scan domain and SSL must be active first
pending_dns is not print ready. txt_challenge on another vercel account blocks certificates. misconfigured after registrar drift 404s live ink. Wait for active status before export.
The encoded URL includes https and a hostname. Phones will refuse a broken certificate more loudly than they refuse a plain marketing page. active status before export is the gate. Everything before active is a DNS or TLS ticket, not a print file.
pending_dns is not print ready: the row exists, the name is registered with the project, records are still wrong. Verifying: records look right, certificates are still issuing. txt_challenge on another vercel account: the name is already claimed elsewhere in that platform. Failed does not hold an allowance slot. Retired stops resolving. Misconfigured after registrar drift is the post-launch killer: it was active, then someone moved nameservers.
Only active and misconfigured currently resolve as a tenant in the host gate, and misconfigured resolves because the codes are real and the fault is DNS. That is sympathy for shoppers, not permission to plate new jobs on a broken name.
Paid options are $1.99, $29, $97, and $197. We do not sell an unpaid tier. Print-in rules: custom scan domain for QR. Host object: custom domain QR code host. Chrome: white label qr scan host.
Website URL generator, codes that never expire, and tracked QR codes are what you encode once TLS is boring. Retail marketing codes are where a padlock name is part of the brand.
How to wait out pending_dns and verifying
Treat the statuses as a checklist the plant can understand.
- Attach the hostname you will encode, typically qr.brand.com.
- If the name is apex, expect www to register alongside it so the pair does not split.
- Put the DNS records where the provision response says. Do not improvise a CNAME from a blog.
- Wait until the status is active, not merely "the dig looks better."
- Create codes against that host. Read https and the host in the downloaded URL.
- Export SVG or 300 dpi PNG or PDF. Do not screenshot /qr-preview.
- Proof on cellular. Confirm the certificate names the host, with no interstitial warning.
- Pause-test the status page on that host, then release pause.
Provisioning that is not configured should refuse with a clear error rather than encode the platform host by accident. Fallback is how you plate the wrong name.
What txt_challenge means on another Vercel account
The hostname is not free in that ecosystem. A TXT record proves you can still edit DNS. Until that challenge completes, certificates will not be the ones you want shoppers to see. Agency retainers hit this when a client already attached the name to a marketing project.
Do not "just print" and hope. Modules do not get a second TLS handshake after the truck leaves.
Apex plus www is the other surprise. Signing off apex while www still fails looks like our bug to a guest who types the www habit. Wait for the pair.
Can you print during misconfigured
Old ink already in shops may keep trying a name that no longer points here. New ink should not join them. Restore DNS, or reprint onto a host that is active.
Misconfigured still holds an allowance slot because the hostname remains on the project. Parking a dead name by ignoring it spends capacity.
Retired stops resolution and can leave the hostname attached. A cutover to another vendor on the same name is a coordinated change, not a toggle.
SSL mistakes that 404 a formed pack
Printing in verifying because the browser on office Wi-Fi cached a good state. Use a phone on cellular, first visit.
Encoding smart-qrcode.com because the client host "would be ready tomorrow." Tomorrow does not rewrite pixels.
Covered finders and screenshot upscales fail before TLS. Fix contrast and size (2 cm at 30 cm, four-module quiet zone) before you blame certificates.
A provider pause 404s or status-pages every host. F91 is not an SSL setting.
How to rehearse TLS the way a shopper will see it
Office laptops trust internal CAs and cache HSTS. Shoppers do not. Rehearse on a factory-reset phone, cellular, Safari and Chrome, first visit. If you see a warning, stop the plant. Custom scan domain and SSL is not done because dig returned the right A record.
If apex is in play, rehearse www as well. Guests type www. A pair that splits is a support queue.
Screenshot the padlock and keep it with the encoded URL. When someone later asks "did we really print qr.brand.com," you have pixels of the certificate and pixels of the symbol.
Do not plate during verifying because a colleague in another country said it worked for them. Their instance cache and their HSTS state are not the nation's.
After launch, a quarterly check is the same cellular first visit. Registrar mail that looks like spam is how domains expire. Expired certificates look like broken codes. They are broken names.
Write the encoded host into the packaging spec as a controlled string, the way you control Pantone. Custom scan domain and SSL then has a document trail when someone "fixes DNS" without telling the plant.
If marketing wants a second hostname for a sub-brand, that is a second allowance slot and a second print family. Do not reuse certificates in conversation as if they were wildcards you never attached.
Keep the platform-host codes that are already in the field on the platform host. A cutover fantasy that every historical carton will move is a reprint programme. Budget it or drop it.
When a certificate warning appears in one browser only, still stop. Shoppers use that browser. Fragmented TLS is not a lab curiosity on launch week.
If legal wants a different hostname per country, that is several hosts and several print families. Do not try to fake it with paths on one certificate. Shoppers read the padlock, not the path. Custom scan domain and SSL is a name in ink, which is why active has to come first.
Record the certificate expiry in the same calendar as the campaign. A surprise expiry is a national 404 with art that still looks perfect. Someone has to own that date. Put the mailbox on the SKU map. A date without an owner is decoration, and decoration does not catch expiry.
When the apex host and a Canva PNG suffice
If the padlock may name the product, skip customer TLS. Hosted types on smart-qrcode.com still edit after print.
If you will never edit or count, skip hosting. Canva or another free static generator is a PNG with the final URL in the modules. Custom scan domain and SSL is then a programme you do not need.
If shoppers must see the client name for the life of the pack, wait for active, then encode, then plate. That is the whole article.
Questions this raises
The hostname already lives on another Vercel account. A TXT record is required before certificates complete. Do not export scan URLs in that state.
You can physically print. Shoppers may 404. Misconfigured means the host was active and DNS has since drifted. Restore records or reprint onto a host you still control.
When the padlock may say smart-qrcode.com, or when a Canva static PNG is enough because you will never edit or count. Custom scan domain and SSL is then extra moving parts.
So the pair does not split. A guest who uses www should not hit a dead certificate while apex works.
No. DNS looks right but certificates are still in flight. Wait for active.
Keep going
The tools and playbooks this post refers to, one click away.
Make the code this post is about
$1.99 for 7 days, then a paid plan. Pick a type, brand it, and edit the destination whenever you like, even after it is printed.