Earlier quoted context omitted.
There is a nicely done 'how it works' on Let's Encrypt: https://letsencrypt.org/how-it-works/
I have read that, but it seems overly complicated. Why not just give the domain owner a private key and a script that is a few lines long. So he can sign a message from them and prove he has the key?
The http or dns challenge/response is more reliable and pretty easy to automate and scale to many domains.