The instinct is to add the domain in the dashboard first, then set up DNS. Do it in that order and the certificate request fires while the name still points nowhere. The authority cannot reach the domain, the check fails, and the platform retries.
The retries are the problem. Let's Encrypt rate-limits failed validations, and a handful of impatient attempts can lock that exact hostname out for an hour or more — usually discovered on the one afternoon you needed it live. The lock is on the name, so no amount of clicking helps.
So: DNS first, dashboard second. Add the record, confirm it resolves, and only then tell the platform about the domain. The certificate then issues on the first attempt, usually in under a minute.
# Confirm the name resolves BEFORE adding it in the dashboard
dig +short launch.yourbrand.com
# pages.example-host.com.
# 203.0.113.10
# Empty output means DNS has not taken effect yet.
# Adding the domain now is what triggers the failed
# certificate attempts — and the rate limit on that hostname.