If an attacker can spoof your DNS records (or if they can simply man in the middle the connection between your server and the internet), then they can generate valid Let’s Encrypt certificates.
If I had the time or inclination, I’d write a transparent https gateway that used let’s encrypt to man-in-the-middle http and https connections to servers behind it.
You could imagine deploying something like that on the edge of AWS for mass surveillance purposes, or maybe a misguided white-hat could use it to “secure” http-only services (it’s an improvement in a defeatist sort of way...)