1. certbot -d --manual --preferred-challenges dns certonly 2. add TXT record 3. check with `dig ` TXT 4. wait. once you see the record, continue.