Comment by notherhack

20 hours ago

Cloudflare refuses to accept most locality based domains as delegated because they aren’t listed in the Public Suffix List[1]. So for example you can’t use Cloudflare DNS or get a TLS cert for it from them.

Fortunately they seem to be one of the few (only?) providers who does that. So use another DNS provider and Letsencrypt and you’re good to go.

[1] https://en.wikipedia.org/wiki/Public_Suffix_List