If you want to protect your IT against attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use and binding, which is easy to set up. https://www.pentagrid.ch/en/blog/domain-verification-bypass-prevention-caa-accounturi/