These are on other VPS with different IP addresses, and they had their own respective Let’s Encrypt SSL certs.
But now as I understand, that CAA record above sort of monopolizes the entire example.com domain, for getting Let’s Encrypt SSL certs! My SSL certs for othersite1.example.com, and othersite2.example.com will eventually expire, and I won’t be able to renew them!
Can I just stop hosting the CAA record, to release the “exclusive lock” (as it were) on my VPS’ static IP addresses (IP4 and IP6), used by the chatmail relay, for obtaining Let’s Encrypt SSL certs?
I didn’t realize I had to “give up” all that domain to my chatmail relay, so to speak.
Assuming subdomains fail to renew because you use different account numbers, adding CAA records for subdomains with correct account numbers should work.