Hi,
Do you have CAA DNS record for your domain? If not I recommend you create it. It should be @ 0 issue "digicert.com" For example, if creating on GoDaddy it would look similar to below:
If you have an existing TXT record for validating your custom domain I recommend you delete that before attempting to delete/re-add your custom domain.
When you create new TXT validation DNS record, make the TTL a low value, say 5-10 minutes (300 or 600 seconds).
You remove/re-add your custom domain by navigating to Custom domains blade. After re-adding domain, generating code, creating DNS TXT record, etc., it may take 10-15 minutes for it to say Validated and then some additional time for new certificate to be deployed out to endpoints.
If you post your domain I could check if CAA record looks correct.
Please reply back with your results.Please click Accept Answer and upvote if the above was helpful.
Thanks.
-TP