Hacker News new | ask | show | jobs
by isclever 1033 days ago
You can buy a domain, put public NS servers on it for the only purpose of doing Letsencrypt DNS validation. Hint: Create root and wildcard (eg domain.ca and *.domain.ca) so you aren't leaking internal DNS records (not that it matters much).

You run an internal DNS server (Pihole + unbound is my combo of choice) which becomes authoritative for your internal LAN.