LE Using Chached DNS lookups during DV process

Have you verified that all nameservers for that zone deliver the TXT records before telling Let's Encrypt to verify the challenges?

1 Like

Yes. Our tool here first checks if all our DNS have acme records propagated correctly and only then sends request to letsencrypt.

The ACME server (boulder) has 1 minute DNS cache, if my recollection is correct.

2 Likes

I believe it's 1 minute or the value of the TTL on the record, whichever is lower.

3 Likes