Unable to get certificate either way

Hello everyone. I'm stuck. First time I cannot get renewed certificate and I don't understand why. Please advise.

My domain is: stogov.spb.ru

I ran this command: certbot -v certonly --manual --preferred-challenges=dns -d stogov.spb.ru

It produced this output:
Waiting for verification...
Challenge failed for domain stogov.spb.ru
dns-01 challenge for stogov.spb.ru

Certbot failed to authenticate some domains (authenticator: manual). The Certificate Authority reported these problems:
Domain: stogov.spb.ru
Type: dns
Detail: DNS problem: query timed out looking up CAA for stogov.spb.ru

=========================================================

I ran this command: certbot -v certonly -d stogov.spb.ru

It produced this output:
Waiting for verification...
Challenge failed for domain stogov.spb.ru
http-01 challenge for stogov.spb.ru

Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
Domain: stogov.spb.ru
Type: dns
Detail: During secondary validation: DNS problem: query timed out looking up A for stogov.spb.ru; DNS problem: query timed out looking up AAAA for stogov.spb.ru

My web server is (include version): lighttpd/1.4.69 (ssl) - a light and fast webserver

The operating system my web server runs on is (include version): cat /etc/debian_version
12.1

My hosting provider, if applicable, is: zomro.com

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): certbot 2.1.0

Welcome to the community @PaulStogov !
It seems there is some problem with the DNS servers of the spb.ru domain. Please read the thread DNS problem: query timed out looking up TXT

6 Likes

I have the same issue - I am trying to renew certificate for mithril.msk.su and get the same error.
I thought .su is banned but mail.elming.su worked well the same day, looks weird.

my certificate is expired now and I don't know what to do, ZeroSSL also doesn't accept my domain