Reading CAA records
0 issue "letsencrypt.org"– Let’s Encrypt may issue normal certificates.0 issuewild "sectigo.com"– Sectigo may issue wildcard certificates.0 iodef "mailto:security@example.com"– where CAs report refused requests.
If a name has no CAA records, CAs check its parent names up to the domain. If none have any, every CA may issue.
Fixing “CAA record prevents issuance”
Add an issue record for the CA you actually use, or remove restrictive records you no longer need. Then request the certificate again.