The primary problem in most cases is the full chain cert not being updated or used in your configuration.
1. Your Let’s Encrypt script might be outdated and isn’t pulling the down the new chain file. This could be your first problem.
2. Your configuration for Apache or whatever app your using is referencing a chain file that isn’t the current one. This could be your second problem. It’s possible you copied the chain file somewhere a long time ago and have been referencing that one instead of the new one that gets pulled down.
The problem will be confusing because your cert will be current, but it still won’t be trusted.
Something like Dovecot can actually use the full chain cert file as the cert file. This will solve that problem instead of only referencing the .crt file, which won’t help, because it won’t be trusted. The full chain needs to be used.