even if the custom hostname is not managed by Cloudflare?
even if the custom hostname is not managed by Cloudflare?
Cloudflare is able to serve a random token from our edge due to the fact that site.example.com has a CNAME in place to $CNAME_TARGET, which ultimately resolves to Cloudflare IPs. If your customer has not yet added the CNAME, the CA will not be able to retrieve the token and the process will not complete.
We will attempt to retry this validation check for a finite period before timing out. Refer to Validation Retry Schedule for more details.

only allows specific hostnames ?



Get a login code emailed to you and now access policies seem to apply as intended. is this an intended feature or a bug?
If the custom hostname is not proxying traffic through Cloudflare, then the custom hostname domain owner will need to add the TXT or HTTP DCV token for the new certificate to validate and issue. As the SaaS provider, you will be responsible for sharing this token with the custom hostname domain owner.