DNS Authorisation for Let's Encrypt
Described in https://tools.ietf.org/html/draft-ietf-acme-acme-06#section-8.4
The problems with mail/webmail/lists subdomains could be obsolete, because a acmechallenge.lists.domain.tld txt record could be challenged.
So no problems with webroots etc.
22
votes

Thank you for your input! We will consider this functionality in upcoming releases if it will be popular.
Everyone, please continue voting for this feature if you consider it important.
— AY