DNS failure requesting verification

Hi,
Using the sign_csr.py from letsencrypt-nosudo client, things seem good until the final stage “Waiting for crm.pro-actionherts.org challenge to pass…” results in failure error:
u’error’: {u’type’: u’urn:acme:error:connection’, u’detail’: u’DNS problem: query timed out looking up CAA for pro-actionherts.org’}

Note the timeout error is for the parent domain. Is that expected? How do we fix the time out issue?

thanks