Almost always DNS propagation, wait 1 hour, recheck. If still broken: (1) Verify the CNAME or A record matches Vercel/Netlify's exact target. (2) Remove and re-add the domain. (3) Check no other provider (Cloudflare proxy mode) is intercepting and serving its own (invalid) cert.
SSL is broken after I attached a custom domain on [Vercel/Netlify]: [paste the error]. Walk me through the checks in order: DNS propagation wait, verifying the CNAME or A record matches the host's exact target, removing and re-adding the domain, and ruling out a Cloudflare proxy serving its own cert.