Yes, 66.133.109.36 is outbound1.letsencrypt.org. You have to unblock it.
Well, they're lying. (Probably.)
https://www.spamhaus.org/query/ip/66.133.109.36
https://www.abuseat.org/lookup.cgi?ip=66.133.109.36
It keeps getting listed because sometimes people try to get Let's Encrypt certificates for botnet C&C domains, so Let's Encrypt connects to the domain to validate it -- just like it connects to your site -- and they incorrectly say that everything that connects to the bad domain must be an infected victim.