CAA SSL certificates Issue with lets encrypt

Topic summary

Issue: Let’s Encrypt cannot issue an SSL certificate for the user’s domain due to current CAA (Certification Authority Authorization) DNS settings.

Details:

  • The user sees an error stating the domain doesn’t permit Let’s Encrypt to provision SSL certificates.
  • They provide screenshots of the error and their CAA DNS records (images are central to understanding the configuration).

Context:

  • CAA records are DNS entries that specify which certificate authorities are allowed to issue certificates for a domain. If Let’s Encrypt is not listed (or issuance is restricted), certificate requests will be blocked.

Request:

  • The user asks why this is happening and seeks help interpreting/fixing their CAA configuration.

Status:

  • No responses or solutions yet. The key question—what in the posted CAA records prevents Let’s Encrypt issuance—remains unanswered. Discussion is open/ongoing.
Summarized with AI on January 9. AI used: gpt-5.

Hello, I have this issue
Your domain doesn’t permit Let’s Encrypt to provision SSL certificates:

this is my CAA

Could anyone help and tell me why I have this issue?
thank you