Amazon Route 53/CloudFront Fails CAA Check

CAA records are not mandatory. A response that indicates no CAA records exists would be accepted.

Most issues with CAA SERVFAILs are due to non-standards-compliant DNS server. Route 53 generally has shown no issue like this in the past, and if you check this recent thread, multiple people report issuance works on domains behind Route 53. That said, other DNS issues, such as DNSSEC misconfigurations, can cause SERVFAIL to occur. You can try this tool, which uses a DNS configuration similar to Let’s Encrypt, with your real domain and review the log output.

A more specific answer would require your real domain in order to run the tests.