I use this solution myself.
I have a domain name I own and only have A records configured for use on internal DNS.
Externally it is managed by cloudflare, and certbot uses the cloudflare plugin to renew certificates before deploying certs to my hardware over telnet