LessEncrypt uses the reverse DNS of the connecting host to control the Common Name and SANs on the cert (multiple SANs can be allocated based on some mapping rules). A connection back to the host for delivery of the cert helps establish a level of trust that the cert is reaching the intended authority.
I'm deploying this in my dev environment and looking for wider review and feedback on it.