Test result for us.oracle.com using http-01
No CAA record on oracle.com (wildcard=false) contains the issuance domain "letsencrypt.org". You must either add an additional record to include "letsencrypt.org" or remove every existing CAA record. A list of the CAA records are provided in the details.
oracle.com. 0 IN CAA 0 issue "symantec.com"
oracle.com. 0 IN CAA 0 issue "digicert.com"
No valid A or AAAA records could be ultimately resolved for us.oracle.com. This means that Let's Encrypt would not be able to to connect to your domain to perform HTTP validation, since it would not know where to connect to.
No A or AAAA records found.