CAA & certificate issuance problem with a previously working setup

Yes, that all looks correct.

If you want to add Let's Encrypt to your base CAA record, but not have it be entirely open, you may want to consider adding an accounturi to the record, which will only allow Let's Encrypt to issue when being requested from a specific ACME account.

4 Likes