The Let's Encrypt HTTP challenge failed: acme error 'urn:acme:error:connection': DNS problem: SERVFAIL looking up A for domain.com

Note that both "primary" and "secondary" name servers are authoritative. An outside observer cannot known which of your NS is primary or not. It just sees all NS servers as authoritative servers.