I use subdomains and a wildcard cert to partly obfuscate this.
I do the same, but I switched from cert-per-subdomain a couple of years ago.
They're either using Passive DNS logs or a historical dataset.
When I stood up some sites last year, I used codenames for the subdomains thinking I was obfuscating a little. I didn't know about the transparency logs until months later.
TIL about Certificate Transparency (they didn't teach that in security school)
Yeah... you have to remember to setup and fully secure the site before LE certs are issued or you're going to have a bad time. Learned that the hard way when I popped a couple dozen wordpress sites in one go.
Because your certificate shows up in the global chain, which triggers all kinds of automated things including bots
On one hand yes, but on the other hand just configuring your server to refuse connections by IP address rather than server name seemed to drop roughly half the bots I ever see.