SERVFAIL looking up A / AAAA during secondary validation for subdomain on Plesk (Windows Server)

Hi everyone,

I am trying to issue a free Let's Encrypt certificate for a subdomain using Plesk on a Windows Server, but the authorization fails during secondary validation with a SERVFAIL error.

Domain name: fieldforce-admin.butsbd.com

The error message I received:

Could not issue an SSL/TLS certificate for fieldforce-admin.butsbd.com
Details:
Could not issue a Let's Encrypt SSL/TLS certificate for fieldforce-admin.butsbd.com. Authorization for the domain failed.
Details:
Invalid response from https://acme-v02.api.letsencrypt.org/acme/authz/1760616402/790195048316
Details:
Type: urn:ietf:params:acme:error:dns
Status: 400
Detail: During secondary validation: DNS problem: SERVFAIL looking up A for fieldforce-admin.butsbd.com - the domain's nameservers may be malfunctioning; DNS problem: SERVFAIL looking up AAAA for fieldforce-admin.butsbd.com - the domain's nameservers may be malfunctioning

Hosting & Environment details:

Control Panel: Plesk
Operating System: Windows Server
Client / Extension: Plesk Let's Encrypt / SSL It! Extension
Validation method: HTTP-01 challenge via Plesk

The subdomain was created recently. It appears there might be a DNS configuration, nameserver synchronization, or DNSSEC issue that triggers SERVFAIL when queried by Let's Encrypt's secondary validation vantage points.

Could anyone please help identify what is misconfigured with the authoritative nameservers or DNS records for this domain?

Thank you in advance for your assistance!

I ran the following test on https://globalping.io/:

Test type: DNS
Target: fieldforce-admin.butsbd.com
Location: World
Limit: 10
Resolver (under the gear icon): 203.76.124.70

203.76.124.70 is the IP address used by both authoritative nameservers for butsbd.com (ns1.butsbd.com and ns2.butsbd.com).

The result shows failures from multiple locations so it looks like there is a problem with the reachability of your DNS server. Unfortunately I don't know how to help you further, but someone else might.

Looks like you got a cert and are now using it. Secondary validation failures are usually geographic based firewalls or some kind of rate limits on your system. I don't see any connection failures currently using the test site @rellem posted so did you find out what the problem was?

Here's output of a current connection test to your domain:

openssl s_client -connect fieldforce-admin.butsbd.com:443

Subject: CN=fieldforce-admin.butsbd.com
Issuer: C=US, O=Let's Encrypt, CN=YR1
Validity
    Not Before: Oct  6 10:12:15 2026 GMT
    Not After : Jan  4 10:12:14 2027 GMT

Cert type: RSA
Signature Algorithm: sha256WithRSAEncryption
Public Key Algorithm: rsaEncryption
    Public-Key: (2048 bit)

X509v3 Subject Alternative Name: 
    DNS: fieldforce-admin.butsbd.com

For reference, here's the results I got when I ran my test earlier today: DNS resolve fieldforce-admin.butsbd.com from World - Globalping