Yeah, but then you can just as well use http-01 with like same effort.
no, because dns supports wildcard certificates, unlike http.
dns-01 is also good for services on a private network.
Ah, good point.