letsencrypt needs to talk to the authoritative name server, but I have all dns traffic redirected to here so we get the SOA using the same request (probably only works by accident) and then make a request to the address listed in the SOA Fix typos in IPv6 addresses