@cf-scott Sorry to bother you in this old thread, but I have exactly the same problem! My domain shows two TXT-Records at _acme-challenge.DOMAIN, but it should use a CNAME-Record for the _acme-challenge subdomain, which is configured correctly! I tried to enable and disable Universal SSL multiple times and waited more than 24h.