Cert order fails with error "During secondary validation: Incorrect TXT record"

Hi @cpu,

Do you host the authoritative nameservers yourself or are you using a third party provider - We do not host the nameservers ourselves, we are using a third party provider. We are doing a queryNS to obtain the nameservers ips and then use them when performing the DNS resolution for the TXT token.

Are your authoritative nameservers 1:1 with the IP addresses or are you perhaps using a setup with IP load balancing or anycast routing? Is there any additional caching in front of the authoritative zones within your infrastructure? - It’s a 3rd party, I don’t have visibility to this information.

What TTL do you set on the TXT records - 2 minutes