I recall that subdomains are their own record inside a DNS, which would imply that anyone can claim that their server is a non-existent subdomain of the real domain

  • Ghoelian@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    8
    ·
    edit-2
    1 month ago

    Yeah, letsencrypt doesn’t do this for example. They do ask for an email address, but that’s just for expiry notices.

    They do require you control the domain, and run it on the server the DNS record points to. When using certbot at least.