“type”: “urn:acme:error:caa”,
“detail”: “Error creating new cert :: While processing CAA for DNS problem: SERVFAIL looking up CAA for - the domain’s nameservers may be malfunctioning”,
“status”: 403

Another similar case:

“detail”: “Error creating new cert :: While processing CAA for CAA record for prevents issuance”,

Your authoritative nameservers produce SERVFAIL when queried for the CAA records of your domain.

There are some other threads that had the exact same issue with the canaldominios nameservers:

Here is a reproduction that you can share with your DNS host’s support:

$ dig +dnssec caa

; <<>> DiG 9.11.5-P4-5.1ubuntu2.1-Ubuntu <<>> +dnssec caa
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 1386
;; flags: qr aa rd ad; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;         IN      CAA

;; ANSWER SECTION:  3600    IN      CNAME

;; AUTHORITY SECTION:          3600    IN      SOA 1 7200 1800 151200 3600

;; Query time: 413 msec
;; WHEN: Fri Mar 06 12:51:52 AEDT 2020
;; MSG SIZE  rcvd: 146

Note the status is SERVFAIL for a direct query to

