New Certificate application failed always

We are using certbot to help our customers new and renew certificates.
All works well while there's one domain that cannot apply the certificate successfully. Can you please help investigate this?

Thanks, Jean

That said, it seems there's something not correcr with the DNS CAA resolving for your website. See: Let's Debug and e.g. | DNSViz


Yeah, the two A addresses point to AWSGlobalAccelerator. This is often used for URL redirect services (like with GoDaddy). The URL Redirect service needs to be disabled and the A record IP pointed directly to their server.

A URL Redirect service would also explain why we see this cert for their HTTPS even though they have a valid DigiCert cert available.

openssl s_client -connect

subject=CN = sni-support-required-for-valid-ssl
issuer=CN = sni-support-required-for-valid-ssl
notBefore=Jul 12 10:32:02 2023 GMT
notAfter=Jul  9 10:32:02 2033 GMT

