Earlier quoted context omitted.
And A and AAAA records are the only way to do HTTP with web browsers ... so?! What makes you think that CNAME or DNAME records are specific to A or AAAA records?!
I'm really struggling to understand what you're recommending. Will you explain how a DNAME works with the Lets Encrypt auth process in a way that makes it as simple as a single CNAME/a-record?
(Obviously doesn't work if they are to keep control over other subdomains of theirhostname.theirdomain, and also, I haven't tried it with DNAMEs, so I don't know whether their implementation is buggy.)