Automatically renew the certificate without control on domain DNS?

YES. To work as the dns challenge that name still must reflect what Lets Encrypt server will look at first

2 Likes