2026-09-17T11:44:13.562399396+02:00 ERROR Error error="renew certificate: could not obtain the certificate for \"beefyvm.com\": resolver: one or more domains had a problem: [pop.beefyvm.com: invalid authorization: acme: error: 400 :: urn:ietfarams:acme:error:dns :: DNS problem: NXDOMAIN looking up A for pop.beefyvm.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for pop.beefyvm.com - check that a DNS record exists for this domain] [smtp.beefyvm.com: invalid authorization: acme: error: 400 :: urn:ietf
arams:acme:error:dns :: DNS problem: NXDOMAIN looking up A for smtp.beefyvm.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for smtp.beefyvm.com - check that a DNS record exists for this domain]"
/var/www/html/.well-known/{rand-name} file and the make a request to curl http://sub.example.com/.well-known/acme-challenge/{rand-name}. In other words it does the same HTTP challenge test that ACME would perform but everything is executed locally (inside the server)./etc/hosts.nameserver 127.0.0.1 in the /etc/resolv.conf) and using external nameservers for this domain.root@vps:~# curl http://beefyvm.com/.well-known/acme-challenge/foobar
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
<snip>
</body></html>
root@vps:~# curl http://pop.beefyvm.com/.well-known/acme-challenge/foobar
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
<snip>
</body></html>
root@vps:~# dig A pop.beefyvm.com @localhost
; <<>> DiG 9.18.49-1~deb12u2-Debian <<>> A pop.beefyvm.com @localhost
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 45962
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; COOKIE: 7fb32a290a0b247f010000006ab40f2b87e54aaf9bdde89a (good)
;; QUESTION SECTION:
;pop.beefyvm.com. IN A
;; AUTHORITY SECTION:
beefyvm.com. 1800 IN SOA ns1.xxxxxx. hostmaster.beefyvm.com. 2026091700 3600 3600 1209600 1800
;; Query time: 0 msec
;; SERVER: ::1#53(localhost) (UDP)
;; WHEN: Wed Sep 23 19:40:59 CEST 2026
;; MSG SIZE rcvd: 140
root@vps:~# cat /etc/resolv.conf
nameserver ip.v4.number.1
nameserver ip.v4.number.2
nameserver ip.v6.number.3
nameserver ip.v6.number.4
root@vps:~# dig A pop.beefyvm.com @ip.v4.number.1
; <<>> DiG 9.18.49-1~deb12u2-Debian <<>> A pop.beefyvm.com @ip.v4.number.1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 39176
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
; EDE: 29: (Result from negative cache for entire name)
;; QUESTION SECTION:
;pop.beefyvm.com. IN A
;; AUTHORITY SECTION:
beefyvm.com. 1224 IN SOA ns1.xxx. hostmaster.beefyvm.com. 2026091700 3600 3600 1209600 1800
;; Query time: 0 msec
;; SERVER: ip.v4.number.1#53(ip.v4.number.1) (UDP)
;; WHEN: Wed Sep 23 19:45:17 CEST 2026
;; MSG SIZE rcvd: 160
root@vps:~# dig A pop.beefyvm.com @ip.v4.number.2
; <<>> DiG 9.18.49-1~deb12u2-Debian <<>> A pop.beefyvm.com @ip.v4.number.2
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 9346
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;pop.beefyvm.com. IN A
;; AUTHORITY SECTION:
beefyvm.com. 1800 IN SOA ns1.xxx. hostmaster.beefyvm.com. 2026091700 3600 3600 1209600 1800
;; Query time: 132 msec
;; SERVER: ip.v4.number.2#53(ip.v4.number.2) (UDP)
;; WHEN: Wed Sep 23 19:45:23 CEST 2026
;; MSG SIZE rcvd: 112
root@vps:~# dig A pop.beefyvm.com @ip.v6.number.3
; <<>> DiG 9.18.49-1~deb12u2-Debian <<>> A pop.beefyvm.com @ip.v6.number.3
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 47547
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
; EDE: 29: (Result from negative cache for entire name)
;; QUESTION SECTION:
;pop.beefyvm.com. IN A
;; AUTHORITY SECTION:
beefyvm.com. 1212 IN SOA ns1.xxx.nl. hostmaster.beefyvm.com. 2026091700 3600 3600 1209600 1800
;; Query time: 0 msec
;; SERVER: ip.v6.number.3#53(ip.v6.number.3) (UDP)
;; WHEN: Wed Sep 23 19:45:29 CEST 2026
;; MSG SIZE rcvd: 160
root@vps:~# dig A pop.beefyvm.com @ip.v6.number.4
; <<>> DiG 9.18.49-1~deb12u2-Debian <<>> A pop.beefyvm.com @ip.v6.number.4
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 45511
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;pop.beefyvm.com. IN A
;; AUTHORITY SECTION:
beefyvm.com. 1787 IN SOA ns1.xxx. hostmaster.beefyvm.com. 2026091700 3600 3600 1209600 1800
;; Query time: 4 msec
;; SERVER: ip.v6.number.4#53(ip.v6.number.4) (UDP)
;; WHEN: Wed Sep 23 19:45:36 CEST 2026
;; MSG SIZE rcvd: 112
root@vps:~# getent hosts pop.beefyvm.com
1234:1234:1234:1234::1 pop.beefyvm.com.xxx.nl
root@vps:~# getent hosts this-should-not-even-exist
2a04:52c0:101:9ce::1 this-should-not-even-exist.xxx.nl
LOCALDOMAIN=. curl [...]
search clause in resolv.conf that points to a domain with wildcard CNAME record.curl, but it uses default system resolver for name resolution, so it is affected by global system resolver configuration.How to debug and investigate the issue?
Internally DA does not usecurl, but it uses default system resolver for name resolution, so it is affected by global system resolver configuration.
[root@poralix etc]# for SUB in www ftp pop mail smtp imap; do echo - $SUB $(dig +short A $SUB.example.domain.com @127.0.0.53); done
- www 88.bb.cc.174
- ftp
- pop
- mail
- smtp
- imap
[root@poralix etc]# for SUB in www ftp pop mail smtp imap; do echo - $SUB $(dig +short A $SUB.example.domain.com @127.0.0.1); done
- www 88.bb.cc.174
- ftp
- pop
- mail
- smtp
- imap
[root@poralix etc]# for SUB in www ftp pop mail smtp imap; do echo - $SUB $(dig +short A $SUB.example.domain.com @localhost); done
- www 88.bb.cc.174
- ftp
- pop
- mail
- smtp
- imap
[root@poralix etc]# for SUB in www ftp pop mail smtp imap; do echo - $SUB $(dig +short A $SUB.example.domain.com @1.1.1.1); done
- www 88.bb.cc.174
- ftp
- pop
- mail
- smtp
- imap
[root@poralix etc]#
/usr/local/bin/lego run --no-bundle --force-cert-domains --no-random-sleep --ari-disable --renew-force --preferred-chain=ISRG Root X1 --accept-tos --key-type=ec256 --server=https://acme-v02.api.letsencrypt.org/directory --path=/usr/local/directadmin/data/lego --http --http.webroot=/var/www/html [email protected] --domains=example.domain.com --domains=www.example.domain.com --domains=mail.example.domain.com --domains=ftp.example.domain.com --domains=pop.example.domain.com --domains=smtp.example.domain.com --domains=imap.example.domain.com
2026-10-09T07:27:27.218486750+02:00 INFO Renewing certificate cert-name=example.domain.com
2026-10-09T07:27:27.218583122+02:00 INFO Changes detected in the certificate configuration.
2026-10-09T07:27:27.218586839+02:00 INFO Trying renewal. cert-name=example.domain.com time-remaining=89d3h22s781414403ns
2026-10-09T07:27:27.717932352+02:00 INFO Obtaining SAN certificate. domains="example.domain.com, www.example.domain.com, mail.example.domain.com, ftp.example.domain.com, pop.example.domain.com, smtp.example.domain.com, imap.example.domain.com"
2026-10-09T07:27:28.949742251+02:00 INFO Authorization is already valid; skipping the challenge. domain=example.domain.com
2026-10-09T07:27:28.949759985+02:00 INFO Use solver. domain=imap.example.domain.com type=http-01
2026-10-09T07:27:28.949774212+02:00 INFO Authorization is already valid; skipping the challenge. domain=www.example.domain.com
2026-10-09T07:27:28.949777317+02:00 INFO Use solver. domain=ftp.example.domain.com type=http-01
2026-10-09T07:27:28.949780724+02:00 INFO Use solver. domain=mail.example.domain.com type=http-01
2026-10-09T07:27:28.949783659+02:00 INFO Use solver. domain=pop.example.domain.com type=http-01
2026-10-09T07:27:28.949786114+02:00 INFO Use solver. domain=smtp.example.domain.com type=http-01
2026-10-09T07:27:28.949792997+02:00 INFO http01: Trying to solve HTTP-01. domain=imap.example.domain.com
2026-10-09T07:27:32.546179149+02:00 INFO http01: Trying to solve HTTP-01. domain=ftp.example.domain.com
2026-10-09T07:27:38.688325070+02:00 INFO http01: Trying to solve HTTP-01. domain=mail.example.domain.com
2026-10-09T07:27:45.678861070+02:00 INFO http01: Trying to solve HTTP-01. domain=pop.example.domain.com
2026-10-09T07:27:50.359022301+02:00 INFO http01: Trying to solve HTTP-01. domain=smtp.example.domain.com
2026-10-09T07:27:55.128341380+02:00 INFO Skipping deactivating of valid authorization. url=https://acme-v02.api.letsencrypt.org/acme/authz/1691471897/782001020686
2026-10-09T07:27:55.279628286+02:00 INFO Skipping deactivating of valid authorization. url=https://acme-v02.api.letsencrypt.org/acme/authz/1691471897/782001020726
2026-10-09T07:27:55.443467091+02:00 INFO Deactivating authorization. url=https://acme-v02.api.letsencrypt.org/acme/authz/1691471897/796254135076
2026-10-09T07:27:55.769669748+02:00 INFO Deactivating authorization. url=https://acme-v02.api.letsencrypt.org/acme/authz/1691471897/796254135086
2026-10-09T07:27:56.095235654+02:00 INFO Deactivating authorization. url=https://acme-v02.api.letsencrypt.org/acme/authz/1691471897/796254135096
2026-10-09T07:27:56.434792472+02:00 INFO Deactivating authorization. url=https://acme-v02.api.letsencrypt.org/acme/authz/1691471897/796254135116
2026-10-09T07:27:56.787461695+02:00 INFO Deactivating authorization. url=https://acme-v02.api.letsencrypt.org/acme/authz/1691471897/796254135126
2026-10-09T07:27:56.990268489+02:00 ERROR Error error="renew certificate: could not obtain the certificate for \"example.domain.com\": resolver: one or more domains had a problem: [ftp.example.domain.com: invalid authorization: acme: error: 400 :: urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up A for ftp.example.domain.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for ftp.example.domain.com - check that a DNS record exists for this domain] [imap.example.domain.com: invalid authorization: acme: error: 400 :: urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up A for imap.example.domain.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for imap.example.domain.com - check that a DNS record exists for this domain] [mail.example.domain.com: invalid authorization: acme: error: 400 :: urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up A for mail.example.domain.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for mail.example.domain.com - check that a DNS record exists for this domain] [pop.example.domain.com: invalid authorization: acme: error: 400 :: urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up A for pop.example.domain.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for pop.example.domain.com - check that a DNS record exists for this domain] [smtp.example.domain.com: invalid authorization: acme: error: 400 :: urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up A for smtp.example.domain.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for smtp.example.domain.com - check that a DNS record exists for this domain]"
exit status 1
Maybegetentcommand would show different results. For example:
getent to my attention. It seems a simple removal ofsearch another-domain.com
/etc/resolv.conf did not take sufficient effect.search .
/etc/resolv.conf. For some reasons the another-domain.com holding its nameservers outside the server and having a wildcard A record in DNS spoiled resolving of other domains.