For the MTM scenario, how would you convince letsencrypt’s CA to issue you a cert for any domain? Don’t you need to complete the challenge in order for the CA to issue you a cert?
Not trivial, but far from impossible for as long as the world maintains that securing the DNS is pointless.