Hi, I'm having the same issue since 2 months. My renewal command results with the following: acme: error: 400: DNS problem: SERVFAIL looking up CAA - the domain's nameservers may be malfunctioning.
I didn't do any changes to the DNS Zone setup in the AWS Router 53 console.
Would you be so kind to describe more precisely which NS values have you changed?
I doubt AWS is going to be using the exact same set of DNS servers for your domain(s) [very low probability]
Thus, I've moved this post to it's own topic.
That said, I don't see how this community can help clarify which name servers you should be using.
That is something only AWS can tell us.
Have you asked them?
Did you open a ticket with them?
Thanks. I will try to change and then see the results.
NOTICE: Name servers for each hosted zone may vary, to check the addresses, go to the Hosted zone details in the AWS Route 53 console and there the list will be available on the right.
UPDATE:
It worked, changing the NS servers resolved the problem. Thanks mate for your help.
You are right, set of DNS may vary for each hosted zone. It also depends on region. The problem has been resolved. I marked the solution, thanks for all of you for help.