Dry-run cert renewal shows incorrect challenge

I don't understand that statement.
challenge requests should be passed through whether HTTP or .

Have you looked at: How to get a Let's Encrypt certificate while using CloudFlare