Confirm the zone
Edit records at the DNS host that answers for the domain — not always the registrar. Nameserver mismatches are the most common delay.
TTL and caches
High TTLs keep old values alive worldwide. Lower TTLs a day before cutover. After the change, wait at least one prior TTL before declaring failure.
Split-horizon DNS
Corporate resolvers may show different answers than public DNS. Verify with public resolvers (1.1.1.1, 8.8.8.8) before opening a support ticket.
When to escalate
If public DNS matches our targets for several hours and SSL still fails, follow SSL still pending or contact support with dig output.