Part of the custom domain process is issuing a certificate for that hostname, which respects the CAA
Part of the custom domain process is issuing a certificate for that hostname, which respects the CAA records on your root domain.
issue "digicert.com", issuewild "digicert.com" and issuewild "letsencrypt.org" then give it another go.
/cdn-cgi/trace?;; ANSWER SECTION:
restream.io. 86400 IN CAA 0 issue "amazonaws.com"
restream.io. 86400 IN CAA 0 issue "awstrust.com"
restream.io. 86400 IN CAA 0 issue "comodoca.com"
restream.io. 86400 IN CAA 0 issue "entrust.net"
restream.io. 86400 IN CAA 0 issue "letsencrypt.org"
restream.io. 86400 IN CAA 0 issuewild "amazon.com"
restream.io. 86400 IN CAA 0 issuewild "amazontrust.com"
restream.io. 86400 IN CAA 0 issuewild "sectigo.com"example.com. IN CAA 0 issue "comodoca.com"
example.com. IN CAA 0 issue "digicert.com"
example.com. IN CAA 0 issue "letsencrypt.org"
example.com. IN CAA 0 issuewild "comodoca.com"
example.com. IN CAA 0 issuewild "digicert.com"
example.com. IN CAA 0 issuewild "letsencrypt.org"issue "digicert.com"issuewild "digicert.com"issuewild "letsencrypt.org"