A certificate for *.example.com covers first-level names such as mail.example.com. It does not cover example.com itself or deeper names such as test.mail.example.com; those need appropriate additional coverage.
cPanel’s Let’s Encrypt AutoSSL plugin cannot issue a wildcard through HTTP validation. Its documented wildcard workflow requires DNS hosted locally or in the cPanel DNS cluster, so an externally hosted DNS zone can prevent that workflow.
Check the required hostnames and authoritative DNS before requesting a wildcard. Do not move working DNS merely to silence an issuance error. Individual-hostname certificates may meet the website’s needs, or a separately configured certificate workflow may be required. Verify the certificate actually presented for every public hostname.
Documentation for this guidance: docs.cpanel.net — the lets encrypt plugin; docs.cpanel.net — guide to ssl.