An Azure service that provides a cloud content delivery network with threat protection.
Hello Dogan Erisen,
Welcome to the Microsoft Q&A and thank you for posting your questions here.
I understand that your AFD custom domain validation stuck in Pending despite correct TXT record on all authoritative nameservers.
This is most likely an Azure Front Door validation or managed-certificate issuance workflow that did not complete correctly.
The way to resolve is to:
- Confirm that the current Azure Front Door
validationProperties.validationTokenstill matches the live_dnsauthTXT value. - Use Refresh on the custom domain validation state, not Regenerate, because regeneration creates a new TXT token and requires another DNS update. - https://stackoverflow.com/questions/76031886/azure-front-door-custom-domain-not-using-correct-cert
- If the domain remains
Pending, Internal team will attend to you as you've open an Azure Support with PCS. - NB: If it's taken longer, regenerate the validation token and update DNS, or use a customer-managed certificate through BYOC as the production workaround. Azure Front Door supports BYOC when the certificate CN or SAN matches the custom domain.
This avoids repeating DNS troubleshooting that has already been completed, protects the customer from unnecessary token rotation, and gives the only reliable path to both service recovery and root-cause confirmation.
I hope this is helpful. Please! Do not hesitate to let me know if you have any other questions, steps or clarifications.
Please do not close the thread by upvoting and accepting the answer if any part of it is helpful.