DNS domains for internal only with public ACME

You can use the DNS challenge. It simply sets a DNS record then deletes it, no need to reach your server from the outside.

(Note that you’ll still need to make sure you configure your network / firewall to properly restrict access in the way you’re describing.)

1 Like