# block .files location ~ /\. { deny all; } # allow Lets encrypt location ~ /.well-known { root YOUR LE DIRECTORY allow all; }