After a lot of try & error I got it running: - ZeroSSL doesn't support the TLS-Challenge, so DNS-Challenge or HTTP-Challenge has to be used - You will need a CAA-record in your DNS settings of your domain containing: 0 issue "sectigo.com" I tried with "zerossl.com" instead of "sectigo.com" first, which didn't work. If you are using Let's Encrypt, too, you also need a CAA record containing 0 issue "letsencrypt.org" - Traefik supports multiple certificate resolvers, but they mu