Letsencrypt expired, and dns errors

with NAT Reflectin enabled, it seems that my email client from internal network can access MAIB with no issues. Therefore I don’t need to enable Split DNS for that for now. However, MAIB status check still doesn’t work…