DNS Authorisation for Let's Encrypt
Described in https://tools.ietf.org/html/draft-ietf-acme-acme-06#section-8.4
The problems with mail/webmail/lists subdomains could be obsolete, because a acmechallenge.lists.domain.tld txt record could be challenged.
So no problems with webroots etc.
24
votes

It's been several years since this feature request was added. Meanwhile a wealth of option is supported by Let's Encrypt through the SSLIt extension. Could you please provide some usage example what is still needed beyond the current solution?
-- PD