Symptom: Dashboard shows both domains Verified + Certificate Issued, but TLS handshake fails with WRONG_VERSION_NUMBER since ~02:15 UTC today (3+ hours). Removing the domains from the service had no effect on edge behavior.
Root evidence: A raw TLS ClientHello to ingress IP 216.24.57.16:443 with SNI=enagafly.cc receives 200+ bytes of 0xFF instead of a ServerHello. The identical ClientHello with SNI=inventory-api.eslitec.com (another custom domain on our account, same IP) receives a normal 16 03 03 ServerHello. A completely unknown SNI receives a proper handshake_failure alert. So the edge recognizes enagafly.cc but its binding is corrupted — this is not a DNS or certificate issuance problem on our side.
Ruled out: DNS correct (Cloudflare DNS-only, CNAME → inventory-frontend-uu53.onrender.com, flattened apex, no CAA). Default hostname inventory-frontend-uu53.onrender.com serves fine. Reproduced from 5 clients across 2 networks.
Ask: Please purge and re-push the edge hostname binding for these two domains.