Automate renew using certbot with dns-01 for firewalled host

I am seeing the same issue. I am nearly convinced that this is a certbot issue. Have a look at this post.

In my case it’s working for the root domain, but not subdomains.

Can you try it for “mydomain.net”? If it is the same problem as mine I think it will work fine.