Still receiving "Action required: Let's Encrypt certificate renewals" emails with older version

The current recommendation for Jessie is to use certbot-auto - https://certbot.eff.org/lets-encrypt/debianjessie-other

Yeah. Numerous bugfixes and changes are not being backported to Debian's 0.12 release, as far as I'm aware.

One example is the v1 API shutdown: End of Life Plan for ACMEv1 , which will affect clients before Jessie is EOL.

Your non-usage of TLS-SNI seems correct, though.