while setting up desc domains to serve some servics using lets encrypt tls i encounter an error such as :
2026/09/17 09:25:53 WaitAuthorization err=acme: authorization error for crytalk.dedyn.io: 400 urn:ietf:params:acme:error:dns: DNS problem: looking up A for crytalk.dedyn.io: DNSSEC: Bogus: validation failure <crytalk.dedyn.io. A IN>: no keys have a DS with algorithm ECDSAP256SHA256 from 45.54.76.1 for key crytalk.dedyn.io. while building chain of trust; DNS problem: looking up AAAA for crytalk.dedyn.io: DNSSEC: Bogus: validation failure <crytalk.dedyn.io. AAAA IN>: no keys have a DS with algorithm ECDSAP256SHA256 from 45.54.76.1 for key crytalk.dedyn.io. while building chain of trust
I must admit, i think i overused the api by creating/deleting the domain automatically via the client,
although I do not know how to solve this issue on my end.
I have waited for hours for caches to clear (dns ttl is 900), it did not help.
To clarify, its a tlsapn-01 validation, not a dns type.
As you said, there was an earlier version of this domain, which was deleted and then recreated it quickly.
Because of the quick timing, the secondary servers had not yet noticed the deletion when the domain was recreated. However, due to earlier changes, the serial number (change counter) of the first domain incarnation was higher than the one of the second incarnation. The secondaries therefore did not notice that the had a stale version, and as a result skipped synchronization.
Apologies that this happened! It looks like a DNSSEC issue on our side, but it’s actually a database synchronization bug (but still our fault).
We have fixed it for your domain, and are working on a permanent solution for the future.