Luke,
Screenshots show different locations of your test files, I guess it's from the same server, and display the issue with accessing acme-challenge.
I don't know your setup, but can it be so that you access different servers from your browser with and without acme-challenge?
ModSecurity in apache/nginx enabled? What if to disable?
[root@323876 ~]# find / -name mod_security
[root@323876 ~]#<IfModule mod_security.c>
  SecFilterEngine Off
  SecFilterScanPOST Off
</IfModule>Anything useful in Apache logs?
[COLOR=#333333]unable to check htaccess file, ensure it is readable and that '/home/censored/' is executable